ScreenConnect Security

    ScreenConnect's 2024 CVEs Were Exploited Within Days. Architecture Matters.

    In February 2024, two ScreenConnect vulnerabilities (CVE-2024-1709, CVSS 10.0; CVE-2024-1708, CVSS 8.4) were weaponised by Black Basta and other ransomware operators within hours of disclosure.

    Is ScreenConnect secure?

    ScreenConnect ships ISO 27001 and SOC 2 attestations and patches CVEs quickly. The challenge is its architecture: relay-based session routing means session media touches ConnectWise infrastructure, and self-hosted deployments are exposed to attackers if the management interface is internet-facing (as the 2024 CVEs proved). DeviceView's WebRTC P2P architecture means session media never traverses our servers, narrowing the blast radius of any control-plane vulnerability.

    Last reviewed: · DeviceView editorial

    Request AccessSee the Full Comparison

    Head-to-head

    Security posture compared

    Architecture, identity controls, and disclosed-CVE history.

    Swipe to compare →
    CapabilityDeviceViewScreenConnect
    Critical CVEs in last 24 monthsNone disclosedCVE-2024-1709 (CVSS 10.0), CVE-2024-1708 (CVSS 8.4)
    Session media routingWebRTC P2P, never via our serversRelay-based by default
    End-to-end encryptionDTLS-SRTP per sessionTLS to relay
    Self-hosted attack surfaceN/A (cloud-only with P2P)Self-hosted exposes management UI
    SSO (SAML)Every planPremium tier
    SCIM provisioningEvery planNot available
    Adaptive MFABuilt-inMFA available
    Conditional accessBuilt-in policiesIP restrictions, role-based
    JIT / time-bound accessBuilt-inNot native
    Session recordingUsage-based add-on, exportablePremium tier
    Audit log SIEM exportSyslog to Splunk/Datadog/SentinelAvailable; tier-dependent
    Multi-tenant isolationCryptographicAccount-based

    Frequently asked questions

    Get Started

    Ready to evaluate DeviceView?

    Request early access to DeviceView.

    DeviceView is a product of DeviceNexus, Inc. Submissions are processed by DeviceNexus.

    We use cookies to understand how you use DeviceView.