CVEFinder.io

CVE-2023-47256

๐Ÿ”ถ medium
๐Ÿ” Scan for this CVE
Summary

ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings

CVSS Score
5.5
Medium
EPSS Score
0.1
Exploit Probability
Published Date
2024-02-01
First Seen: 2026-01-05
๐Ÿ“Š Relative Risk Intelligence

This CVE is Lower Risk - more severe than 31.3% of all 360,673 vulnerabilities in our database.

#247,613
Below average severity
Severity Percentile
๐ŸŽฏ CISA SSVC Assessment Updated: Jun 25, 2024
๐Ÿ” Exploitation Status
None
No known exploits
โš™๏ธ Automatable
NO
Requires human interaction
๐Ÿ’ฅ Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2025-06-17
CVSS Vector 3.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE IDs (Weakness Types)

๐Ÿ“ฆ Affected Products 2

๐Ÿ”— References 2

๐Ÿ”— Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-84869 โ›” critical 9.9 0.7 A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session ... 2026-09-08
CVE-2026-11596 ๐Ÿ”ถ medium 4.7 0.2 In ScreenConnectโ„ข versions prior to 26.2, input validation within the Host Pass creation functionality could allow an ... 2026-06-10
CVE-2026-9089 โš ๏ธ high 8.8 0.3 The ConnectWise Automateโ„ข Agent does not fully verify the authenticity of components obtained during plugin loading an... 2026-05-21
CVE-2025-14823 ๐Ÿ”ถ medium 5.3 0.0 In deployments using the ScreenConnectโ„ข Certificate Signing Extension, encrypted configuration values including an Azu... 2025-12-18
CVE-2025-14265 โ›” critical 9.1 0.1 In versions of ScreenConnectโ„ข prior to 25.8, server-side validation and integrity checks within the extension subsyste... 2025-12-11
CVE-2025-11492 โ›” critical 9.6 0.0 In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on... 2025-10-16
These CVEs affect the same products