← Vulnerability feed

Vulnerability record · CVE-2023-47256 · published 1 February 2024

CVE-2023-47256: Connectwise automate improper authentication vulnerability

Connectwise · Automate

ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings

5.5 CVSS 3.1 Medium EPSS 0.45% · top 63.8% CWE-287 · Improper authentication
5.5CVSS 3.1 base score
0.45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-47256 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-1709ConnectWise ScreenConnect authentication bypass via alternate pathConnectWise ScreenConnect 23.9.7 and earlier contain an authentication bypass (CWE-288) that lets an unauthenticated attacker reach protected functio…KEVEPSS 100%analysed9.9CVE-2026-84869ScreenConnect client allows unauthorized file transfer and execution in remote sessionsA flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host c…KEVEPSS 0.92%analysed8.4CVE-2024-1708ConnectWise ScreenConnect path traversal enabling remote code executionConnectWise ScreenConnect 23.9.7 and earlier contain a path-traversal flaw (CWE-22) that can let an attacker execute remote code or reach confidentia…KEVEPSS 95%analysed7.2CVE-2025-3935ScreenConnect ViewState code injection enables RCEScreenConnect 25.2.3 and earlier rely on ASP.NET ViewState protected by machine keys, and if those keys are compromised an attacker can craft a malic…KEVEPSS 3.5%analysed9.8CVE-2021-35066Connectwise automate xml external entity (xxe) vulnerabilityAn XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.EPSS 1.1%9.8CVE-2020-15027Connectwise automate improper authentication vulnerabilityConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attem…EPSS 1.3%9.1CVE-2025-14265Connectwise screenconnect download of code without integrity check vulnerabilityIn versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation …EPSS 0.37%8.8CVE-2026-9089Connectwise automate download of code without integrity check vulnerabilityThe ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This …EPSS 0.21%

Source: NIST National Vulnerability Database (record CVE-2023-47256), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.