CVEFinder.io

CVE-2023-47257

โš ๏ธ high
๐Ÿ” Scan for this CVE
Summary

ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.

CVSS Score
8.1
High
EPSS Score
5.0
Exploit Probability
Published Date
2024-02-01
First Seen: 2026-01-05
๐Ÿ“Š Relative Risk Intelligence

This CVE is High Risk - more severe than 76.7% of all 360,673 vulnerabilities in our database.

#84,107
Top 25% most severe
Severity Percentile
๐ŸŽฏ CISA SSVC Assessment Updated: May 7, 2025
๐Ÿ” Exploitation Status
None
No known exploits
โš™๏ธ Automatable
NO
Requires human interaction
๐Ÿ’ฅ Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2025-05-07
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE IDs (Weakness Types)

๐Ÿ“ฆ Affected Products 2

๐Ÿ”— References 2

๐Ÿ”— Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-84869 โ›” critical 9.9 0.7 A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session ... 2026-09-08
CVE-2026-11596 ๐Ÿ”ถ medium 4.7 0.2 In ScreenConnectโ„ข versions prior to 26.2, input validation within the Host Pass creation functionality could allow an ... 2026-06-10
CVE-2026-9089 โš ๏ธ high 8.8 0.3 The ConnectWise Automateโ„ข Agent does not fully verify the authenticity of components obtained during plugin loading an... 2026-05-21
CVE-2025-14823 ๐Ÿ”ถ medium 5.3 0.0 In deployments using the ScreenConnectโ„ข Certificate Signing Extension, encrypted configuration values including an Azu... 2025-12-18
CVE-2025-14265 โ›” critical 9.1 0.1 In versions of ScreenConnectโ„ข prior to 25.8, server-side validation and integrity checks within the extension subsyste... 2025-12-11
CVE-2025-11492 โ›” critical 9.6 0.0 In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on... 2025-10-16
These CVEs affect the same products