S4E just found a high [ai] pa ssl inspection control
critical·Product Based Web Vulnerabilities·Updated Apr 30, 2024

CVE-2024-1709 Scanner

Detects 'Authentication Bypass' vulnerability in ConnectWise ScreenConnect affects v. 23.9.7 and prior.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-1709
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ScreenConnectby ConnectWise
0
screenconnectby connectwise
0
Updated Aug 19, 2026View on NVD →
Detail

ConnectWise ScreenConnect is a remote support and remote access software utilized by IT professionals and managed service providers to connect to client systems for troubleshooting and assistance. It facilitates secure remote connections for technical support purposes, enabling efficient problem resolution and system management across various platforms and devices.

The vulnerability detected in ConnectWise ScreenConnect is an Authentication Bypass Using an Alternate Path or Channel flaw present in versions 23.9.7 and prior. This vulnerability allows an attacker to bypass authentication mechanisms and gain unauthorized access to the ScreenConnect application, potentially compromising confidential information or critical systems accessible via the platform.

The vulnerability is exploited by sending a crafted HTTP GET request to the '/SetupWizard.aspx/{{string}}' endpoint of the ScreenConnect application. By manipulating the request parameters, the attacker can bypass the authentication process and access sensitive functionalities intended for authenticated users. Successful exploitation of this vulnerability grants the attacker direct access to confidential information or critical systems managed via ScreenConnect.

Exploiting the Authentication Bypass vulnerability in ConnectWise ScreenConnect can lead to severe consequences, including unauthorized access to sensitive systems and data, potential data breaches, and compromise of critical infrastructure managed by the affected organization. Attackers could exploit this flaw to gain full control over the ScreenConnect application, posing significant risks to the confidentiality, integrity, and availability of the organization's IT assets.

Protect your organization from the risks posed by the Authentication Bypass vulnerability in ConnectWise ScreenConnect by leveraging the comprehensive security scanning capabilities of the S4E platform. Join our platform to identify and remediate critical vulnerabilities like CVE-2024-1709, ensuring the security and integrity of your remote access infrastructure and safeguarding your sensitive data from unauthorized access and exploitation.

 

References

Solution Advice
  • Immediately apply the vendor-provided patches or updates to mitigate the Authentication Bypass vulnerability in ConnectWise ScreenConnect.
  • Implement strong authentication mechanisms, such as multi-factor authentication (MFA), to enhance the security of the ScreenConnect application.
  • Regularly monitor access logs and audit trails for suspicious or unauthorized access attempts to detect and respond to potential exploitation of the vulnerability.
  • Conduct thorough security assessments and penetration testing to identify and address any additional security weaknesses or misconfigurations in the ScreenConnect deployment.
  • Educate users and administrators about the importance of secure authentication practices and the risks associated with unauthorized access to remote support tools like ScreenConnect.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.