Lucene search

K
vulnrichmentCisa-cgVULNRICHMENT:CVE-2024-1708
HistoryFeb 21, 2024 - 3:29 p.m.

CVE-2024-1708 Improper limitation of a pathname to a restricted directory (“path traversal”)

2024-02-2115:29:10
CWE-22
cisa-cg
github.com
6
cve-2024-1708
improper limitation
restricted directory
remote code execution
confidential data
critical systems

CVSS3

8.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

AI Score

8

Confidence

Low

EPSS

0.001

Percentile

19.0%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

total

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker

the ability to execute remote code or directly impact confidential data or critical systems.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:connectwise:screenconnect:-:*:*:*:*:*:*:*"
    ],
    "vendor": "connectwise",
    "product": "screenconnect",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "23.9.7"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

8.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

AI Score

8

Confidence

Low

EPSS

0.001

Percentile

19.0%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

total