Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2020-15008

7.5 · HIGH
Published Jul 7, 2020 connectwise CWE-89 EPSS 0.89% (57th pctl)

Overview

CVE-2020-15008 is a high-severity vulnerability affecting connectwise connectwise_automate. It was published on July 7, 2020 and has a CVSS 3.1 base score of 7.5 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

Technical Description

A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and utilizes the user supplied table name with little validation, the table name can be modified to allow arbitrary update commands to be run. Usage of other SQL injection techniques such as timing attacks, it is possible to perform full data extraction as well. Patched in 2020.7 and in a hotfix for 2019.12.

Remediation

Check the references section for vendor advisories and patches from connectwise. Update connectwise_automate to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
connectwise connectwise_automate >= 0, < 2020.7 Affected

Frequently Asked Questions

What is CVE-2020-15008?

CVE-2020-15008 is a high-severity vulnerability affecting connectwise connectwise_automate. It was published on July 7, 2020 and has a CVSS 3.1 base score of 7.5 (HIGH).

How severe is CVE-2020-15008?

This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2020-15008?

Check the references section for vendor advisories and patches from connectwise. Update connectwise_automate to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2020-15008?

CyberStrike's AI-powered security agents can automatically detect CVE-2020-15008 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.