CVEFinder.io

CVE-2024-1709

β›” critical
πŸ” Scan for this CVE
Summary

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

CVSS Score
10.0
Critical
EPSS Score
94.3
Exploit Probability
Published Date
2024-02-21
First Seen: 2026-01-05
πŸ“Š Relative Risk Intelligence

This CVE is Extremely High Risk - more severe than 100.0% of all 360,673 vulnerabilities in our database.

#1
Top 5% most severe
Severity Percentile
🎯 CISA SSVC Assessment Updated: Feb 24, 2024
πŸ” Exploitation Status
Active
Exploits detected in the wild
βš™οΈ Automatable
YES
Can be exploited automatically
πŸ’₯ Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2026-02-26
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE IDs (Weakness Types)

πŸ“¦ Affected Products 1

πŸ’£ Public Exploits 1 PRO

Loading exploits...

Loading exploit information...

πŸ”— References 11

https://github.com/rapid7/metasploit-framework/pull/...
Issue Tracking Patch Third Party Advisory
https://techcrunch.com/2024/02/21/researchers-warn-h...
Press/Media Coverage Third Party Advisory
https://www.bleepingcomputer.com/news/security/conne...
Press/Media Coverage Third Party Advisory
https://www.securityweek.com/connectwise-confirms-sc...
Press/Media Coverage Third Party Advisory

πŸ”— Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-84869 β›” critical 9.9 0.7 A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session ... 2026-09-08
CVE-2026-11596 πŸ”Ά medium 4.7 0.2 In ScreenConnectβ„’ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an ... 2026-06-10
CVE-2025-14823 πŸ”Ά medium 5.3 0.0 In deployments using the ScreenConnectβ„’ Certificate Signing Extension, encrypted configuration values including an Azu... 2025-12-18
CVE-2025-14265 β›” critical 9.1 0.1 In versions of ScreenConnectβ„’ prior to 25.8, server-side validation and integrity checks within the extension subsyste... 2025-12-11
CVE-2025-3935 ⚠️ high 8.1 12.3 ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web ... 2025-04-25
CVE-2024-1708 ⚠️ high 8.4 53.7 ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker t... 2024-02-21
These CVEs affect the same products