Medium severity5.3NVD Advisory· Published Jan 23, 2020· Updated Jun 17, 2026
CVE-2019-16516
CVE-2019-16516
Description
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account exists for a given username.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:connectwise:control:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:connectwise:control:*:*:*:*:*:*:*:*range: <=19.2.24707
- cpe:2.3:a:connectwise:control:19.3.25270.7185:*:*:*:*:*:*:*
- (no CPE)range: 19.3.25270.7185
- ConnectWise/Controldescription
Patches
Vulnerability mechanics
References
6- packetstormsecurity.com/files/165432/ConnectWise-Control-19.2.24707-Username-Enumeration.htmlnvdExploitThird Party AdvisoryVDB Entry
- blog.huntresslabs.com/validating-the-bishop-fox-findings-in-connectwise-control-9155eec36a34nvdExploitThird Party Advisory
- know.bishopfox.com/advisories/connectwise-controlnvdExploitThird Party Advisory
- know.bishopfox.com/advisoriesnvdThird Party Advisory
- www.crn.com/news/managed-services/connectwise-control-msp-security-vulnerabilities-are-severe-bishop-foxnvdThird Party Advisory
- www.crn.com/slide-shows/managed-services/connectwise-control-attack-chain-exploit-20-questions-for-security-researcher-bishop-foxnvdThird Party Advisory
News mentions
0No linked articles in our index yet.