Known Exploited Vulnerability
8.4
HIGH CVSS 3.1
CVE-2024-1708
ConnectWise ScreenConnect Path Traversal Vulnerability - [Actively Exploited]
Description

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

INFO

Published Date :

Feb. 21, 2024, 4:15 p.m.

Last Modified :

April 28, 2026, 9:44 p.m.

Remotely Exploit :

Yes !

Source :

9119a7d8-5eab-497f-8521-727c672e3725
CISA Notification
CISA KEV (Known Exploited Vulnerabilities)

For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.

Description :

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

Required Action :

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Known Ransomware Campaign Use:

Unknown

Notes :

https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 ; https://nvd.nist.gov/vuln/detail/CVE-2024-1708

Affected Products

The following products are affected by CVE-2024-1708 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Connectwise screenconnect
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH 9119a7d8-5eab-497f-8521-727c672e3725
CVSS 3.1 HIGH [email protected]
Solution
This information is provided by the 3rd party feeds.
  • Upgrade to ConnectWise ScreenConnect Service version 23.9.8 or later
Public PoC/Exploit Available at Github

CVE-2024-1708 has a 11 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2024-1708 is associated with the following CWEs:

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Breach intelligence notes: structured YAML records of breach reports, advisories, and cyber incidents

Go Just HTML HCL CSS JavaScript Go Template Python Shell

Updated: 2 weeks, 4 days ago
1 stars 0 fork 0 watcher
Born at : April 10, 2026, 5:17 a.m. This repo has been linked 78 different CVEs too.

None

PowerShell

Updated: 2 months, 3 weeks ago
0 stars 0 fork 0 watcher
Born at : Feb. 6, 2026, 9:32 p.m. This repo has been linked 4 different CVEs too.

Demo/testing available for free & Everything is for educational purpose only

Python

Updated: 3 months, 3 weeks ago
0 stars 0 fork 0 watcher
Born at : Dec. 18, 2025, 3:46 p.m. This repo has been linked 2 different CVEs too.

A Python tool to check & exploit CVE-2024-1708 & CVE-2024-1709 in ConnectWise ScreenConnect

Python

Updated: 7 months, 1 week ago
0 stars 0 fork 0 watcher
Born at : Sept. 16, 2025, 6:59 p.m. This repo has been linked 2 different CVEs too.

None

Python

Updated: 2 years ago
1 stars 0 fork 0 watcher
Born at : April 2, 2024, 4:58 a.m. This repo has been linked 2 different CVEs too.

CVE-2024-1709 ConnectWise ScreenConnect auth bypass patch WORK 2.0

Updated: 2 years, 1 month ago
3 stars 0 fork 0 watcher
Born at : March 2, 2024, 5:46 a.m. This repo has been linked 2 different CVEs too.

ScreenConnect AuthBypass(cve-2024-1709) --> RCE!!!

attack auth bypass connectwise redteam screenconnect cve-2024-1708 cve-2024-1709

Python

Updated: 10 months ago
104 stars 30 fork 30 watcher
Born at : Feb. 21, 2024, 9:42 a.m. This repo has been linked 2 different CVEs too.

None

Python

Updated: 1 year, 1 month ago
70 stars 18 fork 18 watcher
Born at : Feb. 21, 2024, 5:40 a.m. This repo has been linked 2 different CVEs too.

None

Updated: 1 year, 8 months ago
0 stars 0 fork 0 watcher
Born at : Sept. 4, 2023, 6:14 a.m. This repo has been linked 25 different CVEs too.

A list of dorks for the Netlas.io search engine, with which you can find millions of objects in the boundless IoE. Contains queries to search for IoT elements, protocols, communication tools, remote access, and more. Over time, the list will grow.

osint penetration-testing security-tools

Updated: 5 days, 5 hours ago
203 stars 30 fork 30 watcher
Born at : April 17, 2023, 10:27 a.m. This repo has been linked 66 different CVEs too.

MikroTik Vulnerability Analysis Framework in .NET8

C# CMake C++ Makefile Go

Updated: 1 year, 1 month ago
0 stars 0 fork 0 watcher
Born at : Aug. 5, 2022, 6:28 p.m. This repo has been linked 9 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2024-1708 vulnerability anywhere in the article.

  • The Hacker News
CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws impacting ConnectWise ScreenConnect and Microsoft Windows to its Known Exploited Vulnerabilities (K ... Read more

Published Date: Apr 29, 2026 (6 hours, 36 minutes ago)
  • TheCyberThrone
CISA adds Two vulnerabilities to KEV catalog

April 29, 2026CISA has added two vulnerabilities to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation — CVE-2024-1708, a ConnectWise ScreenConnect path traversal vul ... Read more

Published Date: Apr 29, 2026 (12 hours, 27 minutes ago)
  • The Hacker News
China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware

A China-based threat actor known for deploying Medusa ransomware has been linked to the weaponization of a combination of zero-day and N-day vulnerabilities to orchestrate "high-velocity" attacks and ... Read more

Published Date: Apr 07, 2026 (3 weeks, 1 day ago)
  • Huntress
ESXi Exploitation in the Wild

Background In December 2025, Huntress observed an intrusion leading to the deployment of VMware ESXi exploits. Based on indicators we observed, including the workstation name the threat actor was oper ... Read more

Published Date: Jan 07, 2026 (3 months, 3 weeks ago)
  • Huntress
Tradecraft Tuesday Recap: React2Shell, ClickFix, and the Rise of AI Scams

Every security professional knows the drill. You go home for the holidays and, without volunteering, you become the family’s help desk, incident responder, and fraud advisor. Somewhere between dinner ... Read more

Published Date: Dec 23, 2025 (4 months ago)
  • Huntress
Active Exploitation of Gladinet CentreStack/Triofox Insecure Cryptography Vulnerability

Acknowledgments: Special thanks to John Hammond for his contributions to this investigation and write-up. TL;DR: The AES implementation of Gladinet’s CentreStack and Triofox products contains hardcode ... Read more

Published Date: Dec 10, 2025 (4 months, 2 weeks ago)
  • Huntress
PeerBlight Linux Backdoor Exploits React2Shell CVE-2025-55182

TL;DR: Huntress is seeing threat actors exploit a vulnerability in React Server Components (CVE-2025-55182) across several organizations in our customer base. Attackers have attempted to deploy crypto ... Read more

Published Date: Dec 09, 2025 (4 months, 2 weeks ago)
  • Huntress
Hardening the Hypervisor: Practical Defenses Against Ransomware Targeting ESXi

Hypervisors are the backbone of modern virtualized environments, but when compromised, they can become a force multiplier for attackers. A single breach at this layer can put dozens or even hundreds o ... Read more

Published Date: Dec 08, 2025 (4 months, 3 weeks ago)
  • Huntress
Velociraptor Misuse, Pt. II: The Eye of the Storm

Acknowledgements: Special thanks to Ben Folland, Anna Pham, Michael Tigges, and Anton Ovrutsky for contributing to this investigation and writeup. We recently outlined an incident on November 12 where ... Read more

Published Date: Dec 03, 2025 (4 months, 3 weeks ago)
  • Huntress
Ten Years of Resilience, Innovation & Community-Driven Defense

The world of cybersecurity has been a wild ride over the last decade. As attackers stepped up their game year over year, the security community responded and adapted with resilience and ingenuity to e ... Read more

Published Date: Aug 25, 2025 (8 months ago)
  • Daily CyberSecurity
ShadowSyndicate’s Global Ransomware Empire Blurs Lines Between Cybercrime and Geopolitical Espionage

Attack infrastructure of ShadowSyndicate overlaps with Toneshell, Rustdoor and Koi stealer | Image: Intrinsec In a recent investigation, cybersecurity firm Intrinsec has illuminated the sprawling infr ... Read more

Published Date: Aug 04, 2025 (8 months, 3 weeks ago)
  • AttackIQ
Response to CISA Advisory (AA25-163A): Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider

On June 12, 2025, the U.S. Cybersecurity & Infrastructure Security Agency (CISA) released a Cyber Security Advisory (CSA) which highlights ransomware actors exploiting vulnerabilities in the SimpleHel ... Read more

Published Date: Jun 16, 2025 (10 months, 1 week ago)
  • huntress.com
137 Key Cybersecurity Statistics for 2025 and Beyond

Top cybersecurity facts Staying ahead in cybersecurity means getting the lay of the land—what's working, what's not, and what's changing. This cybersecurity data isn't just numbers; it’s deep insights ... Read more

Published Date: Jun 13, 2025 (10 months, 2 weeks ago)
  • Cyber Security News
Critical ScreenConnect Vulnerability Let Attackers Inject Malicious Code

ConnectWise has released an urgent security patch for its ScreenConnect remote access software to address a serious vulnerability that could allow attackers to execute malicious code on affected syste ... Read more

Published Date: Apr 26, 2025 (1 year ago)
  • Huntress
2024: Revisiting a Year in Threats | Huntress

Before you pop the bubbly and count down to a new year, let’s reminisce for a moment. Looking back on the past 365 days, it was clear cybercriminals had no intention of slowing down. But neither did w ... Read more

Published Date: Dec 31, 2024 (1 year, 3 months ago)
  • Help Net Security
Cybercriminals turn to pen testers to test ransomware efficiency

Threat actors are recruiting pen testers to test and improve the reliability of their ransomware for affiliate programs, according to Cato Networks. Any good developer knows that software needs to be ... Read more

Published Date: Nov 22, 2024 (1 year, 5 months ago)
  • The Register
Ivanti patches exploited admin command execution flaw

The US Cybersecurity and Infrastructure Security Agency (CISA) just added the latest Ivanti weakness to its Known Exploited Vulnerability (KEV) catalog, a situation sure to annoy some – given that it' ... Read more

Published Date: Sep 20, 2024 (1 year, 7 months ago)
  • huntress.com
SlashAndGrab: The ConnectWise ScreenConnect Vulnerability Explained | Huntress

The “exploit” is trivial and embarrassingly easy.  These are words you never want to hear when talking about vulnerabilities in a widely used product, but that’s exactly how John Hammond, Principal Se ... Read more

Published Date: Aug 03, 2024 (1 year, 8 months ago)
  • huntress.com
SlashAndGrab: The ConnectWise ScreenConnect Vulnerability Explained | Huntress

The “exploit” is trivial and embarrassingly easy.  These are words you never want to hear when talking about vulnerabilities in a widely used product, but that’s exactly how John Hammond, Principal Se ... Read more

Published Date: Jul 09, 2024 (1 year, 9 months ago)
  • huntress.com
Attacking MSSQL Servers, Pt. II | Huntress

The AttackOn February 8, 2024, Huntress published the first Attacking MSSQL Servers blog post. On February 23, a Huntress SOC analyst observed similar activity associated with an entirely different en ... Read more

Published Date: Feb 29, 2024 (2 years, 2 months ago)

The following table lists the changes that have been made to the CVE-2024-1708 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Modified Analysis by [email protected]

    Apr. 28, 2026

    Action Type Old Value New Value
    Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1708 Types: Third Party Advisory, US Government Resource
    Added Reference Type CISA-ADP: https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/ Types: Technical Description
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Apr. 28, 2026

    Action Type Old Value New Value
    Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1708
    Added Reference https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/
  • CVE CISA KEV Update by 9119a7d8-5eab-497f-8521-727c672e3725

    Apr. 28, 2026

    Action Type Old Value New Value
    Added Date Added 2026-04-28
    Added Due Date 2026-05-12
    Added Required Action Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    Added Vulnerability Name ConnectWise ScreenConnect Path Traversal Vulnerability
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Nov. 21, 2024

    Action Type Old Value New Value
    Added Reference https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
    Added Reference https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
  • CVE Modified by 9119a7d8-5eab-497f-8521-727c672e3725

    May. 14, 2024

    Action Type Old Value New Value
  • Initial Analysis by [email protected]

    Feb. 22, 2024

    Action Type Old Value New Value
    Added CVSS V3.1 NIST AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
    Changed Reference Type https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 No Types Assigned https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 Vendor Advisory
    Changed Reference Type https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass No Types Assigned https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass Exploit, Third Party Advisory
    Added CWE NIST CWE-22
    Added CPE Configuration OR *cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:* versions up to (excluding) 23.9.8
  • CVE Modified by 9119a7d8-5eab-497f-8521-727c672e3725

    Feb. 21, 2024

    Action Type Old Value New Value
    Added Reference Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass [No types assigned]
  • CVE Received by 9119a7d8-5eab-497f-8521-727c672e3725

    Feb. 21, 2024

    Action Type Old Value New Value
    Added Description ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
    Added Reference Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 [No types assigned]
    Added CWE Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government CWE-22
    Added CVSS V3.1 Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.