Files
CVEs-PoC/2020/CVE-2020-15027.md
T
2024-05-25 21:48:12 +02:00

18 lines
678 B
Markdown

### [CVE-2020-15027](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15027)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12.
### POC
#### Reference
- https://slagle.tech/2020/07/06/cve-2020-15027/
#### Github
No PoCs found on GitHub currently.