← Back to browse · API

CVE-2025-3935

Severity
HIGH
CVSS
8.1
EPSS
0.0342
Risk score
58.6
CISA KEV
Yes
PoC
No
Published
2025-06-02
Modified
2025-06-02
First seen
2026-08-07
Aliases
EUVD-2025-12502, GHSA-QJRP-XR9R-WMRG
Products
ConnectWise:ScreenConnect, ConnectWise:ScreenConnect <25.2.3
Sources
cisa.gov CVE-2025-3935
euvd EUVD-2025-12502

Description

ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allow remote code execution if machine keys are compromised.

References