Back to the feed

~/article/connectwise-screenconnect-improper-privilege-management-and-missing-auth-136run
criticalSource: CISA

ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.

Read at the source

Summary written for cymesh.dev. The full article lives at CISA.

Referenced CVEs

Topics

~/cymesh.net

This is what cymesh.net is for

Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/connectwise-screenconnect-improper-privilege-management-and-missing-auth-136run