PT-2023-18850 · Connectwise · Connectwise Automate

L00Neyhacker

·

Published

2023-02-01

·

Updated

2024-08-02

·

CVE-2023-23130

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Connectwise Automate version 2022.11
Description The issue concerns cleartext authentication, where authentication is performed via HTTP with SSL disabled. This is reportedly controlled by a configuration option, allowing customers to choose HTTP over HTTPS during troubleshooting. The vendor considers this behavior to be by design.
Recommendations For Connectwise Automate version 2022.11, consider enabling SSL to encrypt authentication data and minimize the risk of cleartext authentication exploitation. As a temporary workaround, restrict the use of HTTP for authentication until a more secure configuration can be implemented.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2023-23130

Affected Products

Connectwise Automate