CVE-2019-16516
23.01.2020, 18:15
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account exists for a given username.Enginsight
Vendor | Product | Version |
---|---|---|
connectwise | control | 𝑥 ≤ 19.2.24707 |
connectwise | control | 19.3.25270.7185 |
𝑥
= Vulnerable software versions
References
http://packetstormsecurity.com/files/165432/ConnectWise-Control-19.2.24707-Username-Enumeration.html
https://blog.huntresslabs.com/validating-the-bishop-fox-findings-in-connectwise-control-9155eec36a34
http://packetstormsecurity.com/files/165432/ConnectWise-Control-19.2.24707-Username-Enumeration.html