CVE-2024-1708: ConnectWise ScreenConnect Path Traversal Vulnerability
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker
the ability to execute remote code or directly impact confidential data or critical systems.
Other sources
ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1708?
CVE-2024-1708 is classified as a critical vulnerability due to its potential to allow remote code execution and impact confidential data.
How do I fix CVE-2024-1708?
To remediate CVE-2024-1708, upgrade ConnectWise ScreenConnect to version 23.9.8 or later.
What systems are affected by CVE-2024-1708?
CVE-2024-1708 affects all versions of ConnectWise ScreenConnect prior to 23.9.8.
Can CVE-2024-1708 be exploited remotely?
Yes, CVE-2024-1708 can be exploited remotely by manipulating path traversal mechanisms.
What impact does CVE-2024-1708 have on security?
CVE-2024-1708 may allow attackers to execute remote code, thereby compromising critical systems and data.