s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2024-1708

📛 CVE Title

Improper limitation of a pathname to a restricted directory (“path traversal”)

Description

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

Overview

State
PUBLISHED
Assigner (CNA)
cisa-cg
CVSS severity
HIGH
CVSS score
CVSS 8.4 / 10 8.4 8.4 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Effective score
8.4 / 10 HIGH source: CNA overview
CWE(s)
CWE-22
Reserved
2024-02-21
Published
2024-02-21 15:29 UTC
Last updated
2026-04-29 03:55 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/1xxx/CVE-2024-1708.json
Linked Threat
CVE-2024-1708 — ConnectWise ScreenConnect: ConnectWise ScreenConnect Path Traversal Vulnerability

CISA Known Exploited Vulnerabilities CISA KEV

CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.

Vulnerability name
ConnectWise ScreenConnect Path Traversal Vulnerability
Vendor / project
ConnectWise
Product
ScreenConnect
Date added to KEV
2026-04-28
Remediation due
2026-05-12
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Ransomware campaign use
Known
CISA notes
https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 ; https://nvd.nist.gov/vuln/detail/CVE-2024-1708
CISA listing
www.cisa.gov/known-exploited-vulnerabilities-catalog

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2024-02-21 16:15:50 UTC
NVD last modified
2026-04-28 21:44:53 UTC
NVD CVSS v3.1
CVSS 8.4 / 10 8.4 8.4 / 10 HIGH source: 9119a7d8-5eab-497f-8521-727c672e3725
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Exploitability subscore
1.7 / 10
Impact subscore
6.0 / 10
EPSS score
0.8544 (probability of exploitation in next 30 days)
EPSS percentile
99.38% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24

NVD / KEV / EPSS data refreshed 2026-05-25 01:35 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2024-17442
Assigner
cisa-cg
Published
Feb 21, 2024, 3:29:10 PM
Updated
Apr 29, 2026, 3:55:27 AM
EUVD base score (CVSS 3.1)
8.4 / 10
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
EUVD-reported EPSS
85.7100
Vendors
ConnectWise
Products
ScreenConnect (0 ≤23.9.7)
ScreenConnect
Aliases
GHSA-65x5-26gm-j9pq

ENISA description: ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

EUVD references (2)

Affected products (1)

VendorProductVersionsPlatforms
ConnectWise ScreenConnect 0 (affected)

Affected products — CPE 2.3 (1) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:*

Vendor references (2)

References embedded in the original CVE record by the assigning CNA.

Web references (6)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (6)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Indicators (2)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
cve CVE-2024-1708 no local data 2026-05-14 02:58 UTC
cwe CWE-22 no local data 2026-05-14 02:58 UTC

Flagged vendors

    Remediations (9)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:community.fortinet.com

      What is CVE-2024-1708 ? CVE-2024-1708 is a critical path traversal vulnerability impacting ConnectWise ScreenConnect versions up to 23.9.7. This flaw enables attackers to manipulate file paths, potentially gaining unauthorized access to files or directories located outside the intended restricted directory. Exploitation of this vulnerability could lead to remote code execution or compromise ...

      2026-05-14 06:47 UTC
    • web:cyberpress.org

      The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding the active exploitation of a critical vulnerability in ConnectWise ScreenConnect, tracked as CVE-2024-1708 . On April 28, 2026, the agency added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, signaling confirmed in-the-wild abuse by threat actors. The KEV inclusion underscores the ...

      2026-05-14 06:47 UTC
    • web:nvd.nist.gov

      Official websites use .gov A .gov website belongs to an official government organization in the United States.

      2026-05-14 06:47 UTC
    • web:support.microsoft.com

      How to obtain or download the latest cumulative update package for Linux To update SQL Server 2022 on Linux to the latest CU, you must first have the Cumulative Update repository configured. Then, update your SQL Server packages by using the appropriate platform-specific update command. For installation instructions and direct links to the CU package downloads, see the SQL Server 2022 Release ...

      2026-05-14 06:47 UTC
    • web:www.sentinelone.com

      CVE-2024-1708 is a path traversal vulnerability in ConnectWise ScreenConnect. Learn about its impact, affected versions, and mitigation methods.

      2026-05-14 06:47 UTC
    • web:www.cve.org

      Vulnerability detail for CVE-2024-1708 Notice: Expanded keyword searching of CVE Records (with limitations) is now available in the search box above. Learn more here.

      2026-05-14 06:47 UTC
    • web:www.forbes.com

      As security researchers warn about a dangerous Microsoft Windows update that isn't legitimate, users must pay close attention to what they are actually downloading.

      2026-05-14 06:47 UTC
    • web:www.lumificyber.com

      Discover critical vulnerabilities in ConnectWise ScreenConnect, affecting on-premise servers. Learn about authentication bypass and path traversal risks. Stay informed and update to version 23.9.8 for security.

      2026-05-14 06:47 UTC
    • CISA KEV

      Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-05-12 Known ransomware campaign use: Unknown

      2026-05-14 01:13 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2024-1708.json.

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-1708",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-02-21T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-04-28",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1708"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-04-29T03:55:27.225Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "third-party-advisory"
                ],
                "url": "https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/"
              },
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1708"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-04-28T00:00:00.000Z",
                "value": "CVE-2024-1708 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:48:21.724Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ScreenConnect",
              "vendor": "ConnectWise",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "23.9.8",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "23.9.7 ",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker \n\n<span style=\"background-color: rgb(255, 255, 255);\">the ability to execute remote code or directly impact confidential data or critical systems.</span>\n\n"
                }
              ],
              "value": "ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker \n\nthe ability to execute remote code or directly impact confidential data or critical systems.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-02-21T18:25:58.766Z",
            "orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
            "shortName": "cisa-cg"
          },
          "references": [
            {
              "url": "https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8"
            },
            {
              "url": "https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Improper limitation of a pathname to a restricted directory (\u201cpath traversal\u201d)",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
        "assignerShortName": "cisa-cg",
        "cveId": "CVE-2024-1708",
        "datePublished": "2024-02-21T15:29:10.091Z",
        "dateReserved": "2024-02-21T14:58:56.018Z",
        "dateUpdated": "2026-04-29T03:55:27.225Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }