CVE-2024-1709: ConnectWise ScreenConnect Authentication Bypass Vulnerability
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel
vulnerability, which may allow an attacker direct access to confidential information or
critical systems.
Other sources
ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1709?
CVE-2024-1709 has been rated as a critical severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2024-1709?
To fix CVE-2024-1709, upgrade ConnectWise ScreenConnect to version 23.9.8 or later.
What impact does CVE-2024-1709 have on my system?
CVE-2024-1709 may allow unauthorized users to gain direct access to sensitive information and critical systems.
What versions of ConnectWise ScreenConnect are affected by CVE-2024-1709?
CVE-2024-1709 affects ConnectWise ScreenConnect versions 23.9.7 and earlier.
Is there any known exploitation of CVE-2024-1709?
Yes, CVE-2024-1709 is currently under active attack, highlighting the urgency of applying patches.