A Vulnerability in SimpleHelp Could Allow for Authentication Bypass
A vulnerability has been discovered in SimpleHelp, which could allow for authentication bypass. SimpleHelp is a self-hosted remote support, access, and monitoring software used by IT teams, managed service providers (MSPs), and helpdesks. It enables technicians to securely connect to, troubleshoot, and manage client computers and servers. Successful exploitation of the vulnerability could allow unauthenticated attackers to create a new “Technician” account and use it to remote into managed endpoints, execute scripts, install programs; or view, change, or delete data.
A vulnerability in SimpleHelp allows for authentication bypass, potentially enabling unauthenticated attackers to create new 'Technician' accounts and gain full access to managed endpoints.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HRead the full article
This is a curated summary. The complete article is available at CIS Advisories.