CVE-2025-3426
Last modified
CVE-2025-3426 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is not obfuscated, and no measures are in place to protect against decompilation, disassembly, or debugging. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is not obfuscated, and no measures are in place to protect against decompilation, disassembly, or debugging. As a result, attackers can reverse-engineer the application to gain insights into its internal workings, which can potentially lead to the discovery of sensitive information, business logic flaws, and other vulnerabilities. Utilizing this flaw, the attacker was able to identify the Hardcoded credentials from PortalUsersDatabase.dll, which contains .NET remoting definition. Inside the namespace PortalUsersDatabase, the class Users contains the functions CreateAdmin and CreateService that are used to initialize accounts in the Portal service. Both CreateAdmin and CreateService functions contain a hardcoded encrypted password along with its respective salt that are set with the function SetInitialPasswordAndSalt. This issue affects IntelliSpace Portal: 12 and prior; Advanced Visualization Workspace: 15.
Metrics
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:M/U:Green
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-3426?
How severe is CVE-2025-3426?
How do I fix CVE-2025-3426?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-34254D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain …5.3
- CVE-2025-34255D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain …5.3
- CVE-2025-34256Advantech WISE-DeviceOn Server versions prior to 5.4 contain…9.8
- CVE-2025-34257Advantech WISE-DeviceOn Server versions prior to 5.4 contain…5.4
- CVE-2025-34258Advantech WISE-DeviceOn Server versions prior to 5.4 contain…5.4
- CVE-2025-34259Advantech WISE-DeviceOn Server versions prior to 5.4 contain…5.4
- CVE-2025-34260Advantech WISE-DeviceOn Server versions prior to 5.4 contain…5.4
- CVE-2025-34261Advantech WISE-DeviceOn Server versions prior to 5.4 contain…5.4
- CVE-2025-34262Advantech WISE-DeviceOn Server versions prior to 5.4 contain…5.4
- CVE-2025-34263Advantech WISE-DeviceOn Server versions prior to 5.4 contain…5.4
- CVE-2025-34264Advantech WISE-DeviceOn Server versions prior to 5.4 contain…5.4
- CVE-2025-34265Advantech WISE-DeviceOn Server versions prior to 5.4 contain…5.4
Are you affected by CVE-2025-3426?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
