Unrated severityNVD Advisory· Published Jan 23, 2020· Updated Aug 5, 2024
CVE-2019-16516
CVE-2019-16516
Description
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account exists for a given username.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- ConnectWise/Controldescription
- Range: = 19.3.25270.7185
Patches
Vulnerability mechanics
References
6- packetstormsecurity.com/files/165432/ConnectWise-Control-19.2.24707-Username-Enumeration.htmlmitrex_refsource_MISC
- blog.huntresslabs.com/validating-the-bishop-fox-findings-in-connectwise-control-9155eec36a34mitrex_refsource_MISC
- know.bishopfox.com/advisoriesmitrex_refsource_MISC
- know.bishopfox.com/advisories/connectwise-controlmitrex_refsource_MISC
- www.crn.com/news/managed-services/connectwise-control-msp-security-vulnerabilities-are-severe-bishop-foxmitrex_refsource_MISC
- www.crn.com/slide-shows/managed-services/connectwise-control-attack-chain-exploit-20-questions-for-security-researcher-bishop-foxmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.