First published: Wed Feb 21 2024(Updated: )
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
Credit: 9119a7d8-5eab-497f-8521-727c672e3725 9119a7d8-5eab-497f-8521-727c672e3725
Affected Software | Affected Version | How to fix |
---|---|---|
ScreenConnect | <23.9.8 | |
ScreenConnect |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1709 has been rated as a critical severity vulnerability due to its potential for authentication bypass.
To fix CVE-2024-1709, upgrade ConnectWise ScreenConnect to version 23.9.8 or later.
CVE-2024-1709 may allow unauthorized users to gain direct access to sensitive information and critical systems.
CVE-2024-1709 affects ConnectWise ScreenConnect versions 23.9.7 and earlier.
Yes, CVE-2024-1709 is currently under active attack, highlighting the urgency of applying patches.