kevmap

Coverage › CVE-2024-1708

CVE-2024-1708 Unmapped

ConnectWise ScreenConnect Path Traversal Vulnerability

Vendor / product
ConnectWise — ScreenConnect
Description (CISA)
ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.
Added to KEV
2026-04-28 — after the latest CTID mapping snapshot (2025-07-28)
Due date
2026-05-12
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Known ransomware use
Known
CWE
CWE-22
CISA notes
https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
https://nvd.nist.gov/vuln/detail/CVE-2024-1708
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques

No public source states how this vulnerability is exploited in ATT&CK terms.

The only authoritative CVE → ATT&CK mapping in the open — CTID's Mappings Explorer, pinned to a KEV snapshot of 2025-07-28 and ATT&CK 16.1 — does not include CVE-2024-1708. This entry was added to KEV on 2026-04-28, after that snapshot; of the 283 entries added since, 0 have a mapping. CISA's catalogue carries no technique field. kevmap does not infer techniques from the CWE (CWE-22) — here is why — and does not guess.

This page will change state automatically if a mapping is published. What is shown above is everything CISA publishes about the entry.

Sigma rules tagged with this CVE

2 rules in SigmaHQ carry the tag cve.2024-1708. These are shown as detection content for the CVE itself. Their ATT&CK tags are deliberately not rendered here: a rule author's tag is not an authoritative statement of how the vulnerability is exploited, and this page does not show techniques for unmapped entries.

Author: Matt Anderson, Andrew Schwartz, Caleb Stewart, Huntress · 2024-02-21 · logsource: product=windows category=file_event · 44d7af7e-88e6-4490-be11-55f7ff4d9fc1
This detects file modifications to ASPX and ASHX files within the root of the App_Extensions directory, which is allowed by a ZipSlip vulnerability in versions prior to 23.9.8. This occurs during exploitation of CVE-2024-1708.
CVE tags: CVE-2024-1708
Author: Matt Anderson, Caleb Stewart, Huntress · 2024-02-20 · logsource: product=windows service=security · 4c198a60-7d05-4daf-8bf7-4136fb6f5c62
This detects file modifications to ASPX and ASHX files within the root of the App_Extensions directory, which is allowed by a ZipSlip vulnerability in versions prior to 23.9.8. This occurs during exploitation of CVE-2024-1708. This requires an Advanced Auditing policy to log a successful Windows Event ID 4663 events and with a SACL set on the directory.
CVE tags: CVE-2024-1708