CVE-2024-1708
📛 CVE Title
Improper limitation of a pathname to a restricted directory (“path traversal”)
Description
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- cisa-cg
- CVSS severity
- HIGH
- CVSS score
- 8.4 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H- Effective score
- 8.4 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-22 - Reserved
- 2024-02-21
- Published
- 2024-02-21 15:29 UTC
- Last updated
- 2026-04-29 03:55 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/1xxx/CVE-2024-1708.json
- Linked Threat
- CVE-2024-1708 — ConnectWise ScreenConnect: ConnectWise ScreenConnect Path Traversal Vulnerability
CISA Known Exploited Vulnerabilities CISA KEV
CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.
- Vulnerability name
- ConnectWise ScreenConnect Path Traversal Vulnerability
- Vendor / project
- ConnectWise
- Product
- ScreenConnect
- Date added to KEV
- 2026-04-28
- Remediation due
- 2026-05-12
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Ransomware campaign use
- Known
- CISA notes
- https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 ; https://nvd.nist.gov/vuln/detail/CVE-2024-1708
- CISA listing
- www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2024-02-21 16:15:50 UTC
- NVD last modified
- 2026-04-28 21:44:53 UTC
- NVD CVSS v3.1
- 8.4 / 10 HIGH source: 9119a7d8-5eab-497f-8521-727c672e3725
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H- Exploitability subscore
- 1.7 / 10
- Impact subscore
- 6.0 / 10
- EPSS score
- 0.8544 (probability of exploitation in next 30 days)
- EPSS percentile
- 99.38% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24
NVD / KEV / EPSS data refreshed 2026-05-25 01:35 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2024-17442 - Assigner
- cisa-cg
- Published
- Feb 21, 2024, 3:29:10 PM
- Updated
- Apr 29, 2026, 3:55:27 AM
- EUVD base score (CVSS 3.1)
-
8.4 / 10
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H - EUVD-reported EPSS
- 85.7100
- Vendors
- ConnectWise
- Products
-
ScreenConnect (0 ≤23.9.7)ScreenConnect
- Aliases
-
GHSA-65x5-26gm-j9pq
ENISA description: ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| ConnectWise | ScreenConnect |
0 (affected)
|
— |
Affected products — CPE 2.3 (1) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:*
Vendor references (2)
References embedded in the original CVE record by the assigning CNA.
Web references (6)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- http://cwe.mitre.org/data/definitions/22.html rapid7:cwe.mitre.org
- https://attackerkb.com/topics/CVE-2024-1708 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-17442 rapid7:euvd.enisa.europa.eu
- https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 rapid7:www.connectwise.com
- https://www.cve.org/CVERecord?id=CVE-2024-1708 rapid7:www.cve.org
- https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass rapid7:www.huntress.com
NVD-tagged references (6)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1708 134c704f-9b21-4f2e-91b3-4a467353bcc0 US Government ResourceThird Party Advisory
- https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 9119a7d8-5eab-497f-8521-727c672e3725 Vendor Advisory
- https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
- https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass 9119a7d8-5eab-497f-8521-727c672e3725 ExploitThird Party Advisory
- https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass af854a3a-2127-422b-91ae-364da2661108 ExploitThird Party Advisory
- https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/ 134c704f-9b21-4f2e-91b3-4a467353bcc0 Technical Description
Indicators (2)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| cve |
CVE-2024-1708
|
no local data | 2026-05-14 02:58 UTC |
| cwe |
CWE-22
|
no local data | 2026-05-14 02:58 UTC |
Remediations (9)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:community.fortinet.com
What is CVE-2024-1708 ? CVE-2024-1708 is a critical path traversal vulnerability impacting ConnectWise ScreenConnect versions up to 23.9.7. This flaw enables attackers to manipulate file paths, potentially gaining unauthorized access to files or directories located outside the intended restricted directory. Exploitation of this vulnerability could lead to remote code execution or compromise ...
2026-05-14 06:47 UTC -
web:cyberpress.org
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding the active exploitation of a critical vulnerability in ConnectWise ScreenConnect, tracked as CVE-2024-1708 . On April 28, 2026, the agency added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, signaling confirmed in-the-wild abuse by threat actors. The KEV inclusion underscores the ...
2026-05-14 06:47 UTC -
web:nvd.nist.gov
Official websites use .gov A .gov website belongs to an official government organization in the United States.
2026-05-14 06:47 UTC -
web:support.microsoft.com
How to obtain or download the latest cumulative update package for Linux To update SQL Server 2022 on Linux to the latest CU, you must first have the Cumulative Update repository configured. Then, update your SQL Server packages by using the appropriate platform-specific update command. For installation instructions and direct links to the CU package downloads, see the SQL Server 2022 Release ...
2026-05-14 06:47 UTC -
web:www.sentinelone.com
CVE-2024-1708 is a path traversal vulnerability in ConnectWise ScreenConnect. Learn about its impact, affected versions, and mitigation methods.
2026-05-14 06:47 UTC -
web:www.cve.org
Vulnerability detail for CVE-2024-1708 Notice: Expanded keyword searching of CVE Records (with limitations) is now available in the search box above. Learn more here.
2026-05-14 06:47 UTC -
web:www.forbes.com
As security researchers warn about a dangerous Microsoft Windows update that isn't legitimate, users must pay close attention to what they are actually downloading.
2026-05-14 06:47 UTC -
web:www.lumificyber.com
Discover critical vulnerabilities in ConnectWise ScreenConnect, affecting on-premise servers. Learn about authentication bypass and path traversal risks. Stay informed and update to version 23.9.8 for security.
2026-05-14 06:47 UTC -
CISA KEV
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-05-12 Known ransomware campaign use: Unknown
2026-05-14 01:13 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2024-1708.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-1708",
"options": [
{
"Exploitation": "active"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-02-21T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
},
{
"other": {
"content": {
"dateAdded": "2026-04-28",
"reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1708"
},
"type": "kev"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-04-29T03:55:27.225Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"third-party-advisory"
],
"url": "https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/"
},
{
"tags": [
"government-resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1708"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-04-28T00:00:00.000Z",
"value": "CVE-2024-1708 added to CISA KEV"
}
],
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T18:48:21.724Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ScreenConnect",
"vendor": "ConnectWise",
"versions": [
{
"changes": [
{
"at": "23.9.8",
"status": "unaffected"
}
],
"lessThanOrEqual": "23.9.7 ",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker \n\n<span style=\"background-color: rgb(255, 255, 255);\">the ability to execute remote code or directly impact confidential data or critical systems.</span>\n\n"
}
],
"value": "ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker \n\nthe ability to execute remote code or directly impact confidential data or critical systems.\n\n"
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-02-21T18:25:58.766Z",
"orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"shortName": "cisa-cg"
},
"references": [
{
"url": "https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8"
},
{
"url": "https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Improper limitation of a pathname to a restricted directory (\u201cpath traversal\u201d)",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"assignerShortName": "cisa-cg",
"cveId": "CVE-2024-1708",
"datePublished": "2024-02-21T15:29:10.091Z",
"dateReserved": "2024-02-21T14:58:56.018Z",
"dateUpdated": "2026-04-29T03:55:27.225Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}