CVE-2024-1709 - ScreenConnect Authentication Bypass Exploitation
Detects GET requests to '/SetupWizard.aspx/[anythinghere]' that indicate exploitation of the ScreenConnect vulnerability CVE-2024-1709.
Detection logic
selection
cs-uri-stem|contains: /SetupWizard.aspx/Condition
selectionRaw YAML
title: CVE-2024-1709 - ScreenConnect Authentication Bypass Exploitation
id: d27eabad-9068-401a-b0d6-9eac744d6e67
status: test
description: |
Detects GET requests to '/SetupWizard.aspx/[anythinghere]' that indicate exploitation of the ScreenConnect vulnerability CVE-2024-1709.
references:
- https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
- https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
- https://www.cve.org/CVERecord?id=CVE-2024-1709
author: Matt Anderson, Huntress
date: 2024-02-20
tags:
- attack.initial-access
- attack.persistence
- cve.2024-1709
- detection.emerging-threats
logsource:
category: webserver
detection:
selection:
cs-uri-stem|contains: '/SetupWizard.aspx/'
condition: selection
falsepositives:
- Unknown
level: criticalFalse positives
- Unknown
References
Similar rules
CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit
criticalSame logsource category (webserver)
Oracle WebLogic Exploit
criticalSame logsource category (webserver)
Potential SAP NetViewer Webshell Command Execution
highSame logsource category (webserver)
Rejetto HTTP File Server RCE
highSame logsource category (webserver)