ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedded in plaintext within the binary and used in cryptographic operations without dynamic key management. Once obtained the key can be used to decrypt CSV input files used for authenticated network scanning.
Metrics
Affected Vendors & Products
References
History
Mon, 19 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 19 May 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedded in plaintext within the binary and used in cryptographic operations without dynamic key management. Once obtained the key can be used to decrypt CSV input files used for authenticated network scanning. | |
Title | Hardcoded Key Revealed in ConnectWise Password Encryption Utility | |
Weaknesses | CWE-798 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ConnectWise
Published: 2025-05-19T16:04:34.031Z
Updated: 2025-05-19T16:49:27.487Z
Reserved: 2025-05-16T20:18:46.987Z
Link: CVE-2025-4876

Updated: 2025-05-19T16:49:23.512Z

Status : Awaiting Analysis
Published: 2025-05-19T16:15:35.107
Modified: 2025-05-21T20:25:16.407
Link: CVE-2025-4876

No data.