ConnectWise ScreenConnect Service < 23.9.8 Authentication Bypass (Direct Check)

critical Nessus Plugin ID 190893

Version 1.6

Mar 19, 2024, 6:40 PM

  • Logic Changes (Improving logging to reduce disk space usage)

Plugin Feed: 202403191840

Version 1.5

Mar 19, 2024, 2:37 PM

  • Exploit attributes ("Exploit framework core" set to "True")

Plugin Feed: 202403191437

Version 1.4

Mar 12, 2024, 7:00 PM

  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:H/RL:OF/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:H/RL:O/RC:C")

Plugin Feed: 202403121900

Version 1.4

Mar 19, 2024, 12:36 PM

  • Exploit attributes ("Exploit framework core" set to "True")

Plugin Feed: 202403191236

Version 1.3

Mar 8, 2024, 4:03 PM

  • CISA reference
  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:F/RL:OF/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:F/RL:O/RC:C")
  • Exploit attributes ("Exploit framework metasploit" set to "True")

Plugin Feed: 202403081603

Version 1.2

Mar 8, 2024, 11:22 AM

  • CVSSv2 score source (changed from "manual" to "CVE-2024-1709")
  • CVE (set "CVE" coverage to "CVE-2024-1709")

Plugin Feed: 202403081122

Version 1.1

Feb 27, 2024, 9:22 AM

  • Plugin metadata (Make clear only Service is affected)

Plugin Feed: 202402270922

Version 1.0

Feb 22, 2024, 6:43 PM

  • New

Plugin Feed: 202402221843

* Changelogs are generally available for changes made after Nov 1, 2022