ConnectWise ScreenConnect是ConnectWise公司的一种自托管远程桌面软件应用程序。 ConnectWise ScreenConnect 23.9.7及之前版本存在安全漏洞,该漏洞源于受到使用备用路径或通道绕过身份验证的影响,可能允许攻击者直接访问机密信息或关键系统。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ConnectWise | ScreenConnect | 0 ~ 23.9.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | ScreenConnect AuthBypass(cve-2024-1709) --> RCE!!! | https://github.com/W01fh4cker/ScreenConnect-AuthBypass-RCE | POC Details |
| 2 | A Scanner for CVE-2024-1709 - ConnectWise SecureConnect Authentication Bypass Vulnerability | https://github.com/HussainFathy/CVE-2024-1709 | POC Details |
| 3 | CVE-2024-1709 ConnectWise ScreenConnect auth bypass patch WORK 2.0 | https://github.com/tr1pl3ight/POCv2.0-for-CVE-2024-1709 | POC Details |
| 4 | None | https://github.com/sxyrxyy/CVE-2024-1709-ConnectWise-ScreenConnect-Authentication-Bypass | POC Details |
| 5 | None | https://github.com/cjybao/CVE-2024-1709-and-CVE-2024-1708 | POC Details |
| 6 | Event ID 229 Rule Name SOC262 ScreenConnect Authentication Bypass Exploitation Detected (CVE-2024-1709) | https://github.com/AhmedMansour93/Event-ID-229-Rule-Name-SOC262-CVE-2024-1709- | POC Details |
| 7 | ScreenConnect AuthBypass Mass RCE | https://github.com/AMRICHASFUCK/Mass-CVE-2024-1709 | POC Details |
| 8 | ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-1709.yaml | POC Details |
| 9 | A Python tool to check & exploit CVE-2024-1708 & CVE-2024-1709 in ConnectWise ScreenConnect | https://github.com/Teexo/ScreenConnect-CVE-2024-1709-Exploit | POC Details |
No public POC found.
Login to generate AI POCNo comments yet