CVE-2022-36781: falha de média gravidade em ConnectWise ScreenConnect
ConnectWise - ScreenConnect Session Code Bypass
Publicada em · Atualizada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.3epss 0.6%
probabilidade de exploração
0.6%top 52% das CVEs
exploração observada
nãonenhuma fonte reporta
ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the default configuration. Attackers could exploit this vulnerability to gain unauthorized access by repeatedly attempting access code combinations. ConnectWise has addressed this issue in later versions by implementing rate-limiting controls as a preventive measure against brute force attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Produtos afetados
ConnectWise · ScreenConnectCVEs relacionadas — ConnectWise ScreenConnect
No mesmo produto, das mais perigosas para as menos.
CVE-2024-1709CRITICALAuthentication bypass using an alternate path or channelEPSS 100.0%KEVCVE-2024-1708HIGHImproper limitation of a pathname to a restricted directory (“path traversal”)EPSS 95.4%KEVCVE-2025-3935HIGHScreenConnect Exposure to ASP.NET ViewState Code InjectionEPSS 3.5%KEVCVE-2026-84869CRITICALScreenConnect Client: Guest-to-Host File Execution via File-Transfer ActionsEPSS 0.9%KEVCVE-2025-14265CRITICALImproper server-side validation in ScreenConnect extension frameworkEPSS 0.4%CVE-2026-3564CRITICALScreenConnect Instance Level Cryptographic Material ExposureEPSS 0.3%