Database/Control plane, storage & DevOps

ConnectWise ScreenConnect: Path traversal enabling remote code execution
CVSS 8.4CVE-2024-1708Control plane, storage & DevOpsKnown exploitedcurated
Impact
Path traversal enabling remote code execution; chained with CVE-2024-1709
Who can reach it
Network (remote)
What to do
Control-plane: same patch; audit installed extensions
References
Related entries
- ConnectWise ScreenConnect: ViewState code injectionCVE-2025-3935 · ConnectWise ScreenConnectHigh
- ConnectWise ScreenConnect: Auth bypass via alternate pathCVE-2024-1709 · ConnectWise ScreenConnectCritical
- AMD Graphics Driver - crafted pointer leading to arbitrary writes: A specially crafted pointer passed to the AMDCVE-2024-36352 · AMD Graphics Driver - crafted pointer leading to arbitrary writesHigh
- Dell CloudLink (command injection): Command injection giving a privileged user full control of the CloudLink systemCVE-2025-30479 · Dell CloudLink (command injection)High
- Dell CloudLink (console command injection): Command injection from the console giving shell accessCVE-2025-45379 · Dell CloudLink (console command injection)High
- Renovate (kustomize manager): chart names are injected into helm pull commands, running attacker shell commandsCVE-2026-76229 · Renovate (kustomize manager, helm pull)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.