CVE-2025-42979
Last modified
CVE-2025-42979 is a medium-severity vulnerability rated 5.6/10 on the CVSS scale. The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any attacker who gains access to the user hive of this user�s windows registry could recreate the original password. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any attacker who gains access to the user hive of this user�s windows registry could recreate the original password. There is no impact on integrity or availability of the application
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-42979?
How severe is CVE-2025-42979?
How do I fix CVE-2025-42979?
Are you affected by CVE-2025-42979?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
