CVE-2019-16517
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript running on any domain to interact with the server APIs and perform administrative actions, without the victim's knowledge.
Se detectó un problema en ConnectWise Control (anteriormente se conoce como ScreenConnect) versión 19.3.25270.7185. Se presenta una configuración inapropiada de CORS, que reflejó el Origen proporcionado por las peticiones entrantes. Esto permitió a JavaScript ejecutarse sobre cualquier dominio para interactuar con las API del servidor y llevar a cabo acciones administrativas, sin el conocimiento de la víctima.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-09-19 CVE Reserved
- 2020-01-23 CVE Published
- 2023-10-10 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-346: Origin Validation Error
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://know.bishopfox.com/advisories | Third Party Advisory | |
https://www.crn.com/news/managed-services/connectwise-control-msp-security-vulnerabilities-are-severe-bishop-fox | Third Party Advisory | |
https://www.crn.com/slide-shows/managed-services/connectwise-control-attack-chain-exploit-20-questions-for-security-researcher-bishop-fox | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://blog.huntresslabs.com/validating-the-bishop-fox-findings-in-connectwise-control-9155eec36a34 | 2024-08-05 | |
https://know.bishopfox.com/advisories/connectwise-control | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Connectwise Search vendor "Connectwise" | Control Search vendor "Connectwise" for product "Control" | 19.3.25270.7185 Search vendor "Connectwise" for product "Control" and version "19.3.25270.7185" | - |
Affected
|