ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedded in plaintext within the binary and used in cryptographic operations without dynamic key management. Once obtained the key can be used to decrypt CSV input files used for authenticated network scanning.
References
Configurations
No configuration.
History
21 May 2025, 20:25
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
19 May 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-19 16:15
Updated : 2025-05-21 20:25
NVD link : CVE-2025-4876
Mitre link : CVE-2025-4876
CVE.ORG link : CVE-2025-4876
JSON object : View
Products Affected
No product.
CWE
CWE-798
Use of Hard-coded Credentials