CVE-2025-4876
Last modified
CVE-2025-4876 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedded in plaintext within the binary and used in cryptographic operations without dynamic key management. EPSS estimates a 0.09% chance of exploitation in the next 30 days.
Description
ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedded in plaintext within the binary and used in cryptographic operations without dynamic key management. Once obtained the key can be used to decrypt CSV input files used for authenticated network scanning.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Connectwise | Risk Assessment | < 2023-07-01 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-4876?
How severe is CVE-2025-4876?
How do I fix CVE-2025-4876?
Are you affected by CVE-2025-4876?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
