Critical Authentication Bypass Vulnerability in ScreenConnect (CVE-2024-1709) | UpGuard
ID: e1a13cab-b03b-5c1a-9095-02bbb284bcaf
STIX ID: report--e1a13cab-b03b-5c1a-9095-02bbb284bcaf
Feed Name: UpGuard Blog
Threat Score
ConnectWise disclosed critical vulnerabilities in on-premises ScreenConnect (CVE-2024-1709 — CVSS 10.0 — and CVE-2024-1708 — CVSS 8.4) that can be chained to bypass authentication and achieve remote code execution; multiple PoCs and reported malicious IPs exist, CISA has cataloged the KEV, and organizations are urged to update to the fixed ScreenConnect version and investigate potential compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
