-
EDR / MDRIdentify, contain, respond, and stop malicious activity on endpoints
-
SIEMCentralize threat visibility and analysis, backed by cutting-edge threat intelligence
-
Risk Assessment & Vulnerability ManagementIdentify unknown cyber risks and routinely scan for vulnerabilities
-
Identity ManagementSecure and streamline client access to devices and applications with strong authentication and SSO
-
Cloud App SecurityMonitor and manage security risk for SaaS apps
-
SASEZero trust secure access for users, locations, and devices
-
SOC ServicesProvide 24/7 threat monitoring and response backed by ConnectWise SOC experts
-
Policy ManagementCreate, deploy, and manage client security policies and profiles
-
Incident Response ServiceOn-tap cyber experts to address critical security incidents
-
Cybersecurity GlossaryGuide to the most common, important terms in the industry
ConnectWise Control Broken Access Control
06/15/2021
Vulnerability
CWE-285 – ConnectWise Control Broken Access Control
Severity
Important - Vulnerabilities that could compromise confidential data or other processing resources but require additional access / privilege to do so.
Priority
2 - Vulnerabilities that have elevated risk but exploits are neither known nor anticipated to be imminent. Recommend updates within normal change management timelines but no longer than 30 days.
Affected Versions
21.6 and earlier
Remediation
CLOUD:
Cloud instances are being updated on a rolling schedule, but Cloud Account Admins can manually apply this update through cloud.screenconnect.com.
Follow these steps to upgrade: https://docs.connectwise.com/ConnectWise_Control_Documentation/Get_started/Cloud_portal/Instances_page/Upgrade_a_cloud_instance
ON-PREMISE:
Please note there are some actions you need to take in order to apply this update:
- Navigate to your Administration/License page.
- Expand the Version Check box.
- If you are on 21.6 or an earlier version, you should install the latest build for your current version to receive the latest security updates.
- If your license is out of maintenance, you must upgrade your license before installing the latest supported release of Control.
- Visit our Download page. Download the 21.7 version installation.
- Follow these steps to upgrade: https://docs.connectwise.com/ConnectWise_Control_Documentation/On-premises/Get_started_with_ConnectWise_Control_On-Premise/Upgrade_an_on-premises_installation
Partners who do not wish to upgrade can remediate this issue by removing the global permission RunCommandOutsideSession from AllSessionGroups and applying it only to Support and Access session types or groups as needed.
Documentation for how to modify roles is available in the University at this link:
Additional Info
https://home.connectwise.com/securityBulletin/60c8cc00508a120001cb6e77
Software Updates
Refer to the Remediation section