9
CVE-2026-3564
- EPSS 0.36%
- Veröffentlicht 17.03.2026 14:48:59
- Zuletzt bearbeitet 09.07.2026 18:16:51
- CVE-Watchlists
- Unerledigt
ScreenConnect Instance Level Cryptographic Material Exposure
A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenConnect host and guest client agents are not independently affected by this CVE.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerConnectWise
≫
Produkt
ScreenConnect
Default Statusunaffected
Version
All server versions prior to 26.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.279 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 7d616e1a-3288-43b1-a0dd-0a65d3e70a49 | 9 | 2.2 | 6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://www.connectwise.com/company/trust/security-bulletins/2026-03-17-screenconnect-bulletin