---
cve: "CVE-2024-1709"
severity: "CRITICAL"
cvss: 10.0
epss: "100%"
vendor: "ConnectWise"
kev: true
exploited: true
published: "2024-02-21 16:15:50"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-07T12:18:14+02:00"
---

# CVE-2024-1709

> 10.0 CRITICAL · ⚠️ CISA KEV (928 Tage) · 🔓 Exploited · 🧪 PoC

## Beschreibung

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel

 vulnerability, which may allow an attacker direct access to confidential information or 

critical systems.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8>
- <https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8>
- <https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2>
- <https://www.bleepingcomputer.com/news/security/connectwise-urges-screenconnect-admins-to-patch-critical-rce-flaw/>
- <https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc>
- <https://github.com/rapid7/metasploit-framework/pull/18870>
- <https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/>
- <https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/>
- <https://www.securityweek.com/connectwise-confirms-screenconnect-flaw-under-active-exploitation/>
- <https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass>
- <https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1709>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-1709) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
