CVE-2023-47257
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
01/02/2024
Last modified:
07/05/2025
Description
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:connectwise:automate:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:* | 23.8.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://web.archive.org/web/20240208140218/https://gotham-security.com/screenconnect-cve-2023-47256
- https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.8-security-fix
- https://web.archive.org/web/20240208140218/https://gotham-security.com/screenconnect-cve-2023-47256
- https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.8-security-fix