Description
ConnectWise ScreenConnect has an authentication bypass vulnerability. An attacker can bypass the authentication with a specially crafted path and get access to the setup wizard.
Remediation
Upgrade to the latest version of ScreenConnect
References
Related Vulnerabilities
Coppermine Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2008-3481)
Squid Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-12528)
ownCloud Improper Authentication Vulnerability (CVE-2014-2047)
MySQL Resource Management Errors Vulnerability (CVE-2010-3837)