Skip to main content

Vendor archive

connectwise CVEs

Beta · best-effort

37 CVEs tagged to vendor connectwise8 Critical, 15 High, 14 Medium, 0 Low, 0 Unrated.

CVE-2020-15027

Published Jul 16, 2020

ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15008

Published Jul 7, 2020

A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists du…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14159

Published Jun 15, 2020

By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16517

Published Jan 23, 2020

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-16516

Published Jan 23, 2020

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumeration vulnerability, allowing an unauthenticated attacker t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16515

Published Jan 23, 2020

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. Certain HTTP security headers are not used.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16514

Published Jan 23, 2020

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administrative users could upload an uns…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16513

Published Jan 23, 2020

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16512

Published Jan 23, 2020

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is stored XSS in the Appearance modifier.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18362

Published Feb 5, 2019

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In Feb…

CVSS 9.8 · Critical
Buzz score
25.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2017-11727

Published Jul 31, 2017

services/system_io/actionprocessor/Contact.rails in ConnectWise Manage 2017.5 allows arbitrary client-side JavaScript code execution (involving a ContactCommon field) on victims w…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11726

Published Jul 31, 2017

services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstrated by changing an e-mail address sett…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 26-37 of 37 CVEsPage 2 of 2