Microsoft-HTTPAPI 2.0
tcp/8040
ScreenConnect 24.1.3.8852-4222441908
tcp/8040
The following ConnectWise ScreenConnect is publicly accessible and is vulnerable :
It is critical to update to a safe version as soon as possible since a vulnerability allow remote attackers to create administrative users on the service. Those vulnerabilities are currently used in ransomware campaign and could damage your network.
Reference:
Severity: critical
Fingerprint: 0aef249104a4b7b068d399e6a933d6dca933d6dca933d6dca933d6dca933d6dc
Found vulnerable ConnectWise ScreenConnect: Affected by CW-2024-02-20
Open service 24.33.231.108:8040
2024-12-22 00:29
HTTP/1.1 302 Found Cache-Control: private Content-Length: 134 Content-Type: text/html; charset=utf-8 Location: /SetupWizard.aspx Server: ScreenConnect/24.1.3.8852-4222441908 Microsoft-HTTPAPI/2.0 Date: Sun, 22 Dec 2024 00:29:15 GMT Connection: close Page title: Object moved <html><head><title>Object moved</title></head><body> <h2>Object moved to <a href="/SetupWizard.aspx">here</a>.</h2> </body></html>
Open service 24.33.231.108:8040
2024-12-13 23:07
HTTP/1.1 302 Found Cache-Control: private Content-Length: 134 Content-Type: text/html; charset=utf-8 Location: /SetupWizard.aspx Server: ScreenConnect/24.1.3.8852-4222441908 Microsoft-HTTPAPI/2.0 Date: Fri, 13 Dec 2024 23:07:19 GMT Connection: close Page title: Object moved <html><head><title>Object moved</title></head><body> <h2>Object moved to <a href="/SetupWizard.aspx">here</a>.</h2> </body></html>
Open service 24.33.231.108:8040
2024-12-11 23:59
HTTP/1.1 302 Found Cache-Control: private Content-Length: 134 Content-Type: text/html; charset=utf-8 Location: /SetupWizard.aspx Server: ScreenConnect/24.1.3.8852-4222441908 Microsoft-HTTPAPI/2.0 Date: Wed, 11 Dec 2024 23:59:51 GMT Connection: close Page title: Object moved <html><head><title>Object moved</title></head><body> <h2>Object moved to <a href="/SetupWizard.aspx">here</a>.</h2> </body></html>