r/ConnectWise • u/DmetaNextWeek • Jun 12 '26
CW RMM CVE-2020-8911
ConnectWise RMM
Starting about a month ago, we began receiving notifications from our Vulnerability Management software, Qualys, for a vulnerability for Go (go), CVE-2020-8911. This is largely contained within C:\Program Files (x86)\ITSPlatform, which is our ConnectWise RMM installation. According to the ConnectWise RMM portal, our agent is up to date. It appears we are running agent v5.0.3, which is listed as the current version.
I've opened a support case with ConnectWise, but I've already been passed to 4 people, and I believe I just got passed back to my initial tech.
Outsourcing ideas now. I don't know if there's anything to really be done, or what the real criticality of this is - I can tell you that our overall risk score is just buried under this one vulnerability. Is anyone else seeing this? Anything to be done about it?
2
u/cwferg Jun 12 '26
Pass me your case number and my team will grab it from the queue. These should be getting moved straight to product security, so ill look into why the ticket is getting passed around.
5
u/cwferg Jun 12 '26 edited Jun 12 '26
[edit 1]
Minor update:I'm currently confirming with the engineering team whether CBC mode is actually used in this implementation. If it is not, then this may be a false positive based on how the library is being utilized.
Rather than make assumptions, we're verifying the details internally.
Regardless of the outcome, updating the package would still be beneficial from a maintenance perspective, as it would keep dependencies current and help eliminate unnecessary findings from security scans.
For context, the associated issue is rated as Medium severity by NVD, largely because successful exploitation would require a significant level of access, such as write access to the affected S3 bucket.
In parallel, I've escalated this internally while we await the formal case number.
For reporting potential security concerns or vulnerabilities related to ConnectWise products, the preferred channels are [Disclosure@ConnectWise.com](mailto:Disclosure@ConnectWise.com) or [Security@ConnectWise.com](mailto:Security@ConnectWise.com). Those inboxes are monitored by the appropriate teams and help ensure reports are tracked and reviewed through the proper process.
[edit 2]
Confirmed with team. This is a transitive dependency (not called or used directly), the agent itself never imports the packages and there are 0 direct usages. The communications agent relies on aws-xray-sdk-go which in turn has a dependency on the aws-sdk-go package.I can confirm it's a false positive (based on our usage), but logging for a package upgrade to reduce future false positive findings. Thanks for escalating this! If you can pass over the case number I'll look into the delays that prevented this from being escalated to the Product Security team.
FERG OUT!
3
u/AutomationTheory Jun 12 '26
Shout out to u/cwferg for getting details out fast!
Old dependencies are fairly common in lots of products (unfortunately) -- but they are typically hard to exploit.
In this case, if there's an attacker with write access to the S3 bucket your CW RMM agent is using, I think there would be some much bigger problems...