PT-2022-23620 · Connectwise · Connectwise Screenconnect
Published
2022-09-28
·
Updated
2024-09-16
·
CVE-2022-36781
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ConnectWise ScreenConnect versions 22.6 and below
Description
The issue allows potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the default configuration. Attackers could exploit this to gain unauthorized access by repeatedly attempting access code combinations. This could lead to sensitive data exposure. ConnectWise has addressed this issue in later versions by implementing rate-limiting controls as a preventive measure against brute force attacks.
Recommendations
For ConnectWise ScreenConnect versions 22.6 and below, update to a version later than 22.6 to address the issue by implementing rate-limiting controls. As a temporary workaround, consider configuring rate-limiting controls manually to prevent brute force attacks until a patch is applied. Restrict access to custom access tokens to minimize the risk of exploitation.
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connectwise Screenconnect