Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-16517

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript running on any domain to interact with the server APIs and perform administrative actions, without the victim's knowledge.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.1%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
References
Products affected by CVE-2019-16517
  • Connectwise » Control » Version: 19.3.25270.7185
    cpe:2.3:a:connectwise:control:19.3.25270.7185


Contact Us

Shodan ® - All rights reserved