Authentication Vulnerability in ScreenConnect by ConnectWise
CVE-2025-14823

5.3MEDIUM

Key Information:

Vendor
CVE Published:
18 December 2025

What is CVE-2025-14823?

A vulnerability exists in the ScreenConnect Certificate Signing Extension that could allow unauthenticated users to access encrypted configuration values via a client-facing endpoint. Although sensitive keys remain encrypted and secure at rest, this flaw may expose misleading encrypted data in client responses. To mitigate this issue, it is recommended that users upgrade to version 1.0.12 or higher, ensuring that all sensitive configurations are handled server-side and preventing any encrypted values from being inadvertently rendered on the client side.

Affected Version(s)

ScreenConnect ScreenConnect (all supported versions) when used with the Certificate Signing Extension versions prior to 1.0.12

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Gilliam (Dean Dorton Allen Ford, PLLC)
.
CVE-2025-14823 : Authentication Vulnerability in ScreenConnect by ConnectWise