PT-2023-18850 · Connectwise · Connectwise Automate
L00Neyhacker
·
Publicado
2023-02-01
·
Atualizado
2024-08-02
·
CVE-2023-23130
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Connectwise Automate version 2022.11
Description
The issue concerns cleartext authentication, where authentication is performed via HTTP with SSL disabled. This is reportedly controlled by a configuration option, allowing customers to choose HTTP over HTTPS during troubleshooting. The vendor considers this behavior to be by design.
Recommendations
For Connectwise Automate version 2022.11, consider enabling SSL to encrypt authentication data and minimize the risk of cleartext authentication exploitation. As a temporary workaround, restrict the use of HTTP for authentication until a more secure configuration can be implemented.
Exploit
Correção
Cleartext Transmission of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Connectwise Automate