VulnerabilityModified
CVE-2019-16516
There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account exists for a given username.
MEDIUM 5.3EPSS 19.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 19.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account exists for a given username.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 19.10% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- connectwise/control
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/165432/ConnectWise-Control-19.2.24707-Username-Enumeration.htmlExploit, Third Party Advisory, VDB Entry
- https://blog.huntresslabs.com/validating-the-bishop-fox-findings-in-connectwise-control-9155eec36a34Exploit, Third Party Advisory
- https://know.bishopfox.com/advisoriesThird Party Advisory
- https://know.bishopfox.com/advisories/connectwise-controlExploit, Third Party Advisory
- https://www.crn.com/news/managed-services/connectwise-control-msp-security-vulnerabilities-are-severe-bishop-foxThird Party Advisory
- https://www.crn.com/slide-shows/managed-services/connectwise-control-attack-chain-exploit-20-questions-for-security-researcher-bishop-foxThird Party Advisory
- http://packetstormsecurity.com/files/165432/ConnectWise-Control-19.2.24707-Username-Enumeration.htmlExploit, Third Party Advisory, VDB Entry
- https://blog.huntresslabs.com/validating-the-bishop-fox-findings-in-connectwise-control-9155eec36a34Exploit, Third Party Advisory
- https://know.bishopfox.com/advisoriesThird Party Advisory
- https://know.bishopfox.com/advisories/connectwise-controlExploit, Third Party Advisory
- https://www.crn.com/news/managed-services/connectwise-control-msp-security-vulnerabilities-are-severe-bishop-foxThird Party Advisory
- https://www.crn.com/slide-shows/managed-services/connectwise-control-attack-chain-exploit-20-questions-for-security-researcher-bishop-foxThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.