CVE-2021-32582
Last modified
CVE-2021-32582 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extract database information or administrative credentials from an instance via crafted monitor status responses.. EPSS estimates a 1.13% chance of exploitation in the next 30 days.
Description
An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extract database information or administrative credentials from an instance via crafted monitor status responses.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Connectwise | Connectwise Automate | < 2021.5 |
References
- https://home.connectwise.com/securityBulletin/609a9dd75cb8450001e85369Permissions Required, Vendor Advisory
- https://www.connectwise.com/company/trust/security-bulletinsVendor Advisory
- https://home.connectwise.com/securityBulletin/609a9dd75cb8450001e85369Permissions Required, Vendor Advisory
- https://www.connectwise.com/company/trust/security-bulletinsVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-32582?
How severe is CVE-2021-32582?
How do I fix CVE-2021-32582?
Are you affected by CVE-2021-32582?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
