PT-2022-23620 · Connectwise · Connectwise Screenconnect

Published

2022-09-28

·

Updated

2024-09-16

·

CVE-2022-36781

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ConnectWise ScreenConnect versions 22.6 and below
Description The issue allows potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the default configuration. Attackers could exploit this to gain unauthorized access by repeatedly attempting access code combinations. This could lead to sensitive data exposure. ConnectWise has addressed this issue in later versions by implementing rate-limiting controls as a preventive measure against brute force attacks.
Recommendations For ConnectWise ScreenConnect versions 22.6 and below, update to a version later than 22.6 to address the issue by implementing rate-limiting controls. As a temporary workaround, consider configuring rate-limiting controls manually to prevent brute force attacks until a patch is applied. Restrict access to custom access tokens to minimize the risk of exploitation.

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2022-36781

Affected Products

Connectwise Screenconnect