CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2024-1709

Critical Severity|Connectwise
90
SVRS
10.0
CVSSv3
0.99959
EPSS
TAGS
In The WildKnown Ransomware Campaign UseExploit AvaliableCISA KEV
VECTOR STRING
CVSS:3.1AV:NAC:LPR:NUI:NS:CC:HI:HA:H
PUBLICATION DATE2024-02-21
LAST MODIFIED2025-10-21

Deep CVE Analysis in Progress

The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.

Security Intelligence Brief

1. What is this vulnerability and why does it matter?
This vulnerability, identified as CVE-2024-1709, is an authentication bypass in ConnectWise ScreenConnect versions 23.9.7 and prior. It falls under the category of "Authentication Bypass Using an Alternate Path or Channel" (CWE-288). This vulnerability is extremely critical because it allows an attacker to bypass standard authentication mechanisms, potentially granting them direct, unauthorized access to confidential information or critical systems. The ability to circumvent authentication is a severe security flaw that can lead to complete system compromise and data exfiltration, making it a high-priority concern for any organization utilizing the affected software.
2. What are the CVSS score, severity level, and disclosure details?
  • CVSS Score: 10
  • Severity Level: Critical. A CVSS score of 10 indicates the highest possible severity, signifying that the vulnerability is easily exploitable and has a devastating impact.
  • Disclosure Details: The vulnerability was published on 2024-02-21 at 15:36:03 UTC. It was last modified on 2025-10-21 at 23:05:24 UTC.
3. Which products, vendors, systems, and versions are affected?
  • Vendor: ConnectWise
  • Product: ScreenConnect
  • Affected Versions: All versions up to and including 23.9.7 are affected. This means versions 23.9.7 and all prior versions are vulnerable.
4. What is the technical root cause and attack vector?
The technical root cause of CVE-2024-1709 is an Authentication Bypass Using an Alternate Path or Channel, categorized under CWE-288. This implies that the software contains a flaw where an attacker can utilize an alternative, unintended, or poorly secured path or channel within the application to circumvent the intended authentication process. The attack vector involves exploiting this alternate path to gain unauthorized access without providing valid credentials.
5. How can this vulnerability be exploited?
This vulnerability can be exploited by an attacker leveraging an "Alternate Path or Channel" to bypass the normal authentication procedures of ConnectWise ScreenConnect. By doing so, the attacker can gain unauthorized direct access to confidential information or critical systems managed by the ScreenConnect instance. The fact that "Active exploits have been published to exploit the vulnerability" indicates that the method of exploitation is publicly known and can be readily utilized by malicious actors.
7. How can vulnerable systems be detected?
Vulnerable systems can be detected by identifying the installed version of ConnectWise ScreenConnect. Any instance running version 23.9.7 or any version prior to it is considered vulnerable to CVE-2024-1709. System administrators should check their ScreenConnect installations and verify their current version numbers.
10. What public intelligence references and advisories exist?
The primary public intelligence reference is the CVE entry itself: CVE-2024-1709. This entry provides the description, severity, and affected versions. The disclosure date of February 21, 2024, indicates public awareness since that time. Furthermore, the explicit statement that "Active exploits have been published to exploit the vulnerability" serves as a critical piece of intelligence, confirming that exploit code is publicly available, increasing the urgency of remediation.
11. What is the risk assessment and urgency level?
The risk assessment for CVE-2024-1709 is extremely high, and the urgency level is critical. This assessment is based on several factors:
  • CVSS Score of 10: This indicates maximum severity and impact.
  • Authentication Bypass: The nature of the vulnerability allows attackers to completely circumvent security controls to gain unauthorized access.
  • Direct Access to Confidential Information or Critical Systems: The potential impact involves compromise of sensitive data and core infrastructure.
  • Active Exploits Published: The existence of public exploits means that the vulnerability is actively being targeted, significantly increasing the likelihood of successful attacks.
Organizations using ConnectWise ScreenConnect 23.9.7 and prior must treat this as an immediate and critical threat requiring urgent remediation.
TypeIndicatorDate
IP
47.123.7.2062025-02-14Search on IOC Radar
IP
47.115.51.442025-02-20Search on IOC Radar
IP
45.13.199.2092024-09-25Search on IOC Radar
IP
103.201.129.1302021-09-03Search on IOC Radar
HOSTNAME
dscriy.chtq.net2025-02-27Search on IOC Radar
HOSTNAME
news.imaginerjp.com2025-06-12Search on IOC Radar
HOSTNAME
sentinelxdr.us2025-06-12Search on IOC Radar
TitleSoftware LinkDate
tdawg506/ScreenConnect-CVE-2024-1709-Exploithttps://github.com/tdawg506/ScreenConnect-CVE-2024-1709-Exploit2025-09-16
Teexo/ScreenConnect-CVE-2024-1709-Exploithttps://github.com/Teexo/ScreenConnect-CVE-2024-1709-Exploit2025-09-16
AhmedMansour93/Event-ID-229-Rule-Name-SOC262-CVE-2024-1709-https://github.com/AhmedMansour93/Event-ID-229-Rule-Name-SOC262-CVE-2024-1709-2024-09-12
codeb0ss/CVE-2024-1709-PoChttps://github.com/codeb0ss/CVE-2024-1709-PoC2024-05-24
tr1pl3ight/POCv2.0-for-CVE-2024-1709https://github.com/tr1pl3ight/POCv2.0-for-CVE-2024-17092024-03-02
ConnectWise ScreenConnect Authentication Bypass Vulnerabilityhttps://www.cisa.gov/search?g=CVE-2024-17092024-02-22
watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-pochttps://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc2024-02-21
SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs
China-Nexus Nation State Actors Exploit SAP NetWeaver (CVE-2025-31324) to Target Critical Infrastructures - EclecticIQ Blog
2025-05-13
China-Nexus Nation State Actors Exploit SAP NetWeaver (CVE-2025-31324) to Target Critical Infrastructures - EclecticIQ Blog | News Content: Arda Büyükkaya May 13, 2025 China-Nexus Nation State Actors Exploit SAP NetWeaver (CVE-2025-31324) to Target Critical Infrastructures Intelligence Research Executive Summary EclecticIQ analysts assess with high confidence that, in April 2025, China-nexus nation-state APTs (advanced persistent threat) launched high-temp exploitation campaigns against critical infrastructure networks by targeting SAP NetWeaver Visual Composer. Actors leveraged CVE-2025-31324 [1], an unauthenticated file upload vulnerability that enables remote code execution (RCE). This assessment is based on a publicly
cve-2025-31324cve-2024-8963cve-2023-46747cve-2024-9380
Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations - Microsoft
2026-04-06
Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations - Microsoft | News Content: The financially motivated cybercriminal actor tracked by Microsoft Threat Intelligence as Storm-1175 operates high-velocity ransomware campaigns that weaponize N-days, targeting vulnerable, web-facing systems during the window between vulnerability disclosure and widespread patch adoption. Following successful exploitation, Storm-1175 rapidly moves from initial access to data exfiltration and deployment of Medusa ransomware, often within a few days and, in some cases, within 24 hours. The threat actor’s high operational tempo and proficiency in identifying exposed perimeter assets have proven
cve-2024-27199cve-2024-21887cve-2023-46805cve-2025-52691
Fast, smart, and private: Group-IB introduces AI Assistant
2025-04-18
Fast, smart, and private: Group-IB introduces AI Assistant | Our new LLM-powered chatbot is designed for efficiency and security. Discover how Group-IB AI Assistant enhances threat intelligence workflows and provides security teams with instant insights — without compromising privacy. | News Content: Introduction Love it or hate it, AI in cybersecurity is no longer hype or hypothetical. You can either harness its power or deal with the consequences. Attackers are already using AI to launch faster and more convincing phishing campaigns, generate deepfake videos, and exploit vulnerabilities at scale. Meanwhile, defenders are bogged down by slow, manual workflows and
group-ib.comrssforumnews
ISC StormCast for Thursday, February 22nd, 2024
Dr. Johannes B. Ullrich2024-02-22
ISC StormCast for Thursday, February 22nd, 2024 | Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Archive.org Phish; ScreenConnect PoC; Post Quantum iMessage;Phishing Pages Hosted on Archive.org https://isc.sans.edu/forums/diary/Phishing%20pages%20hosted%20on%20archive.org/30676/ ScreenConnect Authentication Bypass Exploit CVE-2024-1709 CVE-2024-1708) https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass iMessage with PQ3 https://security.apple.com/blog/imessage-pq3/
sans.edurssforumnews
CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV - The Hacker News
2026-04-29
CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV - The Hacker News | News Content: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws impacting ConnectWise ScreenConnect and Microsoft Windows to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2024-1708 (CVSS score: 8.4) - A path traversal vulnerability in ConnectWise ScreenConnect that could allow an attacker to execute remote code or directly impact confidential data and critical systems. (Fixed in February 2024) CVE-2026-32202 (CVSS score: 4.3) - A protection mechanism failure vulnerability in Microsoft
apt28storm-1175medusagoogle.com
Breach Roundup: US Cyber Command Flags Election Threats - GovInfoSecurity
2026-05-01
Breach Roundup: US Cyber Command Flags Election Threats - GovInfoSecurity | News Content: Also, HexDex Arrest, Black Axe Crackdown, LeRobot RCE Flaw Every week, ISMG rounds up cybersecurity incidents and breaches around the world. This week, U.S. Cyber Command warned of likely foreign interference in upcoming elections, medical device maker Stryker discussed the financial impact of its hack, a convicted Vastaamo hacker sought a final appeal and French authorities arrested a prolific data thief tied to multiple breaches. Swiss police dismantled a Black Axe fraud network, while a China-linked "Spamouflage" campaign targeted Tibetan elections. Meanwhile, active exploitation of ConnectWise and Windows
google.comrssforumnews
Microsoft flags China-based hackers using vicious new 'rapid attack' zero-days - TechRadar
2026-04-08
Microsoft flags China-based hackers using vicious new 'rapid attack' zero-days - TechRadar | News Content: Storm-1175 rapidly moves from access to ransomware deployment Exploits zero-days and n-days across multiple products Targets healthcare, finance, education, and professional services Chinese-speaking hacking collective Storm-1175 is moving fast, going from initial access to full system compromise and data exfiltration in weeks, and sometimes in less than 24 hours, experts have warned. A new report from Microsoft claims the group was seen leveraging multiple flaws, both zero-days and n-days, in their activities. In some cases, they would even
google.comrssforumnews
avatar
GoCocoaAI@GoCocoaAI
18 days ago
The window closed BLUF: The time between vulnerability disclosure and active exploitation is now measured in days, not sprints. Traditional patch cycles were not built for this. 1. Two days is not a cycle The disclosure-to-KEV gap on CVE-2024-1709 (ConnectWise ScreenConnect,
avatar
GoCocoaAI@GoCocoaAI
18 days ago
Source trail for the operator desk. BleepingComputer on why alert speed is the new constraint: https://t.co/dENojQZSQj — CVE-2024-1709 NVD entry: https://t.co/C8uldfNMUF https://t.co/OfH3tJp0hp
avatar
Adam@cybernews231
2026-05-12
ConnectWise ScreenConnect hit CISA's Known Exploited Vulnerabilities list. CVE-2024-1708 + CVE-2024-1709 chained together. Path traversal meets authentication bypass. Unpatched instances are sitting ducks for ransomware groups.
avatar
Lyrie.ai@lyrie_ai
2026-05-03
CVE-2024-1709: ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices.
avatar
Inferlume@inferlume_hq
2026-04-30
CVE-2024-1708 in ConnectWise ScreenConnect was also added to KEV. Storm-1175, a China nexus actor, chains it with CVE-2024-1709 to deliver Medusa ransomware. Healthcare and managed service providers are the confirmed target profile.
avatar
ThreatCluster@threatcluster
2026-04-29
BREAKING: CISA adds actively exploited ScreenConnect flaws CVE-2024-1708 and CVE-2024-1709 to KEV catalog, confirming ongoing attacks via SlashAndGrab exploit chain. https://t.co/CZ2FUn0lnU
avatar
Lyrie.ai@lyrie_ai
2026-04-29
CVE-2024-1709: CVE-2024-1709: ConnectWise ScreenConnect Supply Chain Breach Vector... (10.0 → 23.9.7)
avatar
Lyrie.ai@lyrie_ai
2026-04-29
CVE-2024-1709 is a perfect-score authentication bypass in ConnectWise ScreenConnect, a remote access platform deployed across 1+ million organizations globally. The vulnerability allows unauthenticated attackers to gain full administrative access by sending a single HTTP…
avatar
Lyrie.ai@lyrie_ai
2026-04-29
CVE-2024-1709 is a trust topology vulnerability — the tool designed to provide secure remote access becomes the breach vector. In traditional attack models, compromising ScreenConnect grants access to one organization. In MSP deployments, it cascades to hundreds of…
avatar
777@SteveAJ777
2026-04-25
I cannot post the full snort rules but u might want to add them, . [CVE-2024-1709] ConnectWise ScreenConnect Authentication Bypass  . [CVE-2024-21887] Ivanti Connect Secure Command Injection  . [CVE-2024-3400] Palo Alto PAN-OS GlobalProtect Command Injection
Configuration 1
TypeVendorProduct
AppConnectwisescreenconnect
ReferenceLink
GITHUBhttps://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
GITHUBhttps://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
GITHUBhttps://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
GITHUBhttps://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
GITHUBhttps://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
GITHUBhttps://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
9119A7D8-5EAB-497F-8521-727C672E3725https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
9119A7D8-5EAB-497F-8521-727C672E3725https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
AF854A3A-2127-422B-91AE-364DA2661108https://github.com/rapid7/metasploit-framework/pull/18870
AF854A3A-2127-422B-91AE-364DA2661108https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
AF854A3A-2127-422B-91AE-364DA2661108https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
AF854A3A-2127-422B-91AE-364DA2661108https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
AF854A3A-2127-422B-91AE-364DA2661108https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/rapid7/metasploit-framework/pull/18870
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
9119A7D8-5EAB-497F-8521-727C672E3725https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
9119A7D8-5EAB-497F-8521-727C672E3725https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
AF854A3A-2127-422B-91AE-364DA2661108https://github.com/rapid7/metasploit-framework/pull/18870
AF854A3A-2127-422B-91AE-364DA2661108https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
AF854A3A-2127-422B-91AE-364DA2661108https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
AF854A3A-2127-422B-91AE-364DA2661108https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
AF854A3A-2127-422B-91AE-364DA2661108https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/rapid7/metasploit-framework/pull/18870
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
9119A7D8-5EAB-497F-8521-727C672E3725https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.bleepingcomputer.com/news/security/connectwise-urges-screenconnect-admins-to-patch-critical-rce-flaw/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
9119A7D8-5EAB-497F-8521-727C672E3725https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
9119A7D8-5EAB-497F-8521-727C672E3725https://www.securityweek.com/connectwise-confirms-screenconnect-flaw-under-active-exploitation/
GITHUBhttps://github.com/rapid7/metasploit-framework/pull/18870
GITHUBhttps://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
GITHUBhttps://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
GITHUBhttps://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
GITHUBhttps://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
GITHUBhttps://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
GITHUBhttps://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
GITHUBhttps://www.bleepingcomputer.com/news/security/connectwise-urges-screenconnect-admins-to-patch-critical-rce-flaw/
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/rapid7/metasploit-framework/pull/18870
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
9119A7D8-5EAB-497F-8521-727C672E3725https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.bleepingcomputer.com/news/security/connectwise-urges-screenconnect-admins-to-patch-critical-rce-flaw/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
9119A7D8-5EAB-497F-8521-727C672E3725https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
9119A7D8-5EAB-497F-8521-727C672E3725https://www.securityweek.com/connectwise-confirms-screenconnect-flaw-under-active-exploitation/
AF854A3A-2127-422B-91AE-364DA2661108https://github.com/rapid7/metasploit-framework/pull/18870
AF854A3A-2127-422B-91AE-364DA2661108https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
AF854A3A-2127-422B-91AE-364DA2661108https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
AF854A3A-2127-422B-91AE-364DA2661108https://www.bleepingcomputer.com/news/security/connectwise-urges-screenconnect-admins-to-patch-critical-rce-flaw/
AF854A3A-2127-422B-91AE-364DA2661108https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
AF854A3A-2127-422B-91AE-364DA2661108https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
AF854A3A-2127-422B-91AE-364DA2661108https://www.securityweek.com/connectwise-confirms-screenconnect-flaw-under-active-exploitation/
GITHUBhttps://github.com/rapid7/metasploit-framework/pull/18870
GITHUBhttps://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
GITHUBhttps://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
GITHUBhttps://www.bleepingcomputer.com/news/security/connectwise-urges-screenconnect-admins-to-patch-critical-rce-flaw/
GITHUBhttps://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
GITHUBhttps://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
GITHUBhttps://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
GITHUBhttps://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
GITHUBhttps://www.securityweek.com/connectwise-confirms-screenconnect-flaw-under-active-exploitation/
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
9119A7D8-5EAB-497F-8521-727C672E3725https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
9119A7D8-5EAB-497F-8521-727C672E3725https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
AF854A3A-2127-422B-91AE-364DA2661108https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
AF854A3A-2127-422B-91AE-364DA2661108https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
AF854A3A-2127-422B-91AE-364DA2661108https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
AF854A3A-2127-422B-91AE-364DA2661108https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/rapid7/metasploit-framework/pull/18870
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
9119A7D8-5EAB-497F-8521-727C672E3725https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
9119A7D8-5EAB-497F-8521-727C672E3725https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
AF854A3A-2127-422B-91AE-364DA2661108https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
AF854A3A-2127-422B-91AE-364DA2661108https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
AF854A3A-2127-422B-91AE-364DA2661108https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
AF854A3A-2127-422B-91AE-364DA2661108https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
9119A7D8-5EAB-497F-8521-727C672E3725https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
AF854A3A-2127-422B-91AE-364DA2661108https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
AF854A3A-2127-422B-91AE-364DA2661108https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
AF854A3A-2127-422B-91AE-364DA2661108https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
AF854A3A-2127-422B-91AE-364DA2661108https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/rapid7/metasploit-framework/pull/18870
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
9119A7D8-5EAB-497F-8521-727C672E3725https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
9119A7D8-5EAB-497F-8521-727C672E3725https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
AF854A3A-2127-422B-91AE-364DA2661108https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
AF854A3A-2127-422B-91AE-364DA2661108https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
AF854A3A-2127-422B-91AE-364DA2661108https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/rapid7/metasploit-framework/pull/18870
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
9119A7D8-5EAB-497F-8521-727C672E3725https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
9119A7D8-5EAB-497F-8521-727C672E3725https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
AF854A3A-2127-422B-91AE-364DA2661108https://github.com/rapid7/metasploit-framework/pull/18870
AF854A3A-2127-422B-91AE-364DA2661108https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
AF854A3A-2127-422B-91AE-364DA2661108https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
AF854A3A-2127-422B-91AE-364DA2661108https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
134C704F-9B21-4F2E-91B3-4A467353BCC0https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1709
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/rapid7/metasploit-framework/pull/18870
9119A7D8-5EAB-497F-8521-727C672E3725https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
9119A7D8-5EAB-497F-8521-727C672E3725https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
9119A7D8-5EAB-497F-8521-727C672E3725https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
AF854A3A-2127-422B-91AE-364DA2661108https://github.com/rapid7/metasploit-framework/pull/18870
AF854A3A-2127-422B-91AE-364DA2661108https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
AF854A3A-2127-422B-91AE-364DA2661108https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/
AF854A3A-2127-422B-91AE-364DA2661108https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
AF854A3A-2127-422B-91AE-364DA2661108https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
CWE IDCWE NameDescription
CWE-288Authentication Bypass Using an Alternate Path or ChannelA product requires authentication, but the product has an alternate path or channel that does not require authentication.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.