ScreenConnect Security
ScreenConnect's 2024 CVEs Were Exploited Within Days. Architecture Matters.
In February 2024, two ScreenConnect vulnerabilities (CVE-2024-1709, CVSS 10.0; CVE-2024-1708, CVSS 8.4) were weaponised by Black Basta and other ransomware operators within hours of disclosure.
Is ScreenConnect secure?
ScreenConnect ships ISO 27001 and SOC 2 attestations and patches CVEs quickly. The challenge is its architecture: relay-based session routing means session media touches ConnectWise infrastructure, and self-hosted deployments are exposed to attackers if the management interface is internet-facing (as the 2024 CVEs proved). DeviceView's WebRTC P2P architecture means session media never traverses our servers, narrowing the blast radius of any control-plane vulnerability.
Last reviewed: · DeviceView editorial
Head-to-head
Security posture compared
Architecture, identity controls, and disclosed-CVE history.
| Capability | DeviceView | ScreenConnect |
|---|---|---|
| Critical CVEs in last 24 months | None disclosed | CVE-2024-1709 (CVSS 10.0), CVE-2024-1708 (CVSS 8.4) |
| Session media routing | WebRTC P2P, never via our servers | Relay-based by default |
| End-to-end encryption | DTLS-SRTP per session | TLS to relay |
| Self-hosted attack surface | N/A (cloud-only with P2P) | Self-hosted exposes management UI |
| SSO (SAML) | Every plan | Premium tier |
| SCIM provisioning | Every plan | Not available |
| Adaptive MFA | Built-in | MFA available |
| Conditional access | Built-in policies | IP restrictions, role-based |
| JIT / time-bound access | Built-in | Not native |
| Session recording | Usage-based add-on, exportable | Premium tier |
| Audit log SIEM export | Syslog to Splunk/Datadog/Sentinel | Available; tier-dependent |
| Multi-tenant isolation | Cryptographic | Account-based |