VYPR

Connectwise Automate

by Connectwise

CVEs (3)

  • CVE-2021-32582HigJun 17, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extract database information or administrative credentials from an instance via crafted monitor status…

  • CVE-2020-15008HigJul 7, 2020
    risk 0.49cvss 7.5epss 0.01

    A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and…

  • CVE-2026-6066HigApr 20, 2026
    risk 0.46cvss 7.1epss 0.00

    ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based…