/Vulnerability Library

ConnectWise ScreenConnect <= 23.9.7 - Path Traversal

CVE-2024-1708
Verified

Description

ConnectWise ScreenConnect 23.9.7 and prior contain a path traversal caused by improper handling of user input, letting attackers execute remote code or access confidential data, exploit requires network access.

Severity

High

CVSS Score

8.4

Exploit Probability

95%

Affected Product

screenconnect

Published Date

August 19, 2026

Template Author

popy21

CVE-2024-1708.yaml
8.4Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CVE ID:
cve-2024-1708
CWE ID:
cwe-22

References

https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypasshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1708https://nvd.nist.gov/vuln/detail/CVE-2024-1708

Remediation Steps

Update to the latest version of ConnectWise ScreenConnect.