CVE-2021-32582

high

Description

An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extract database information or administrative credentials from an instance via crafted monitor status responses.

References

https://www.connectwise.com/platform/unified-management/automate

https://www.connectwise.com/company/trust/security-bulletins

https://home.connectwise.com/securityBulletin/609a9dd75cb8450001e85369

Details

Source: Mitre, NVD

Published: 2021-06-17

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

EPSS

EPSS: 0.00511