CVE Tools

CVE-2024-1709

Authentication bypass using an alternate path or channel

Published: Feb 21, 2024Updated: Feb 26, 2026 Sources: CVE List NVD BDUCWE-288

Description

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

In plain language

AI Act now

CVE-2024-1709 is an authentication-bypass flaw in ConnectWise ScreenConnect that lets an attacker access sensitive data or control the system without logging in—so any small business using ScreenConnect 23.9.7 or older should treat it as a serious emergency and patch immediately.

Executive summary

CVE-2024-1709 is an authentication bypass in ConnectWise ScreenConnect where attackers can reach protected functionality over the network without authentication (bypassing login restrictions), enabling access to confidential data or system-impacting actions on unpatched versions (fixed in 23.9.8).

If affected, business impact
Full system compromise without loginConfidential data exposureRemote control of systemsRansomware campaign risk

What to do now

  1. Check your ConnectWise ScreenConnect version and confirm whether it is 23.9.7 or earlier.
  2. Upgrade ScreenConnect to 23.9.8 (or the next vendor-recommended fixed version) immediately.
  3. If you cannot patch right now, disable or restrict external access to ScreenConnect (allow only trusted internal networks/IPs) until an upgrade is completed.
  4. After upgrading, verify the service is running the new version and review access logs for any suspicious “no-login” access attempts.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:CC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 1 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Feb 22, 2024
Remediation due:Feb 29, 2024
Ransomware:Known ransomware use

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

3 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

References

and 9 more references View all →
4

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2024-1709 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store