Vulnerabilities
Vulnerable Software
Connectwise:  >> Automate  >> 2020.0  Security Vulnerabilities
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
CVSS Score
9.8
EPSS Score
0.004
Published
2021-06-21
The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.
CVSS Score
8.8
EPSS Score
0.002
Published
2020-10-09
ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12.
CVSS Score
9.8
EPSS Score
0.004
Published
2020-07-16


Contact Us

Shodan ® - All rights reserved