A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and utilizes the user supplied table name with little validation, the table name can be modified to allow arbitrary update commands to be run. Usage of other SQL injection techniques such as timing attacks, it is possible to perform full data extraction as well. Patched in 2020.7 and in a hotfix for 2019.12.
Conclusion & alert: CVE-2020-15008 is rated Moderate Risk (49.7/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.89%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.26% | 0.89% | +0.63% |
| 2 | 2025-03-30 | 0.50% | 0.26% | -0.24% |
| 3 | 2025-03-29 | — | 0.50% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
1.6 | 5.9 | [email protected] |
| 6.0 | 2.0 | MEDIUM |
|
6.8 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| connectwise | connectwise_automate | < 2020.7 | cpe:2.3:a:connectwise:connectwise_automate:*:*:*:*:*:*:*:* |
| connectwise | connectwise_automate | 2019.12 | cpe:2.3:a:connectwise:connectwise_automate:2019.12:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://slagle.tech/2020/07/06/cve-2020-15008/ | Not Applicable |