First published: Thu Feb 01 2024(Updated: )
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ConnectWise Automate | ||
ConnectWise ScreenConnect | <23.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47257 has a high severity level due to the potential for remote code execution by man-in-the-middle attackers.
To mitigate CVE-2023-47257, upgrade to the latest version of ConnectWise ScreenConnect that addresses this vulnerability.
CVE-2023-47257 affects ConnectWise ScreenConnect versions up to 23.8.4 and ConnectWise Automate without specified versions.
CVE-2023-47257 allows man-in-the-middle attacks that can lead to remote code execution.
Yes, there is a patch included in the latest updates for ConnectWise ScreenConnect to fix CVE-2023-47257.