cvedb.io
CVE-2025-4876
MEDIUM · CVSS 6
EPSS exploitation probability: 0%
Published 2025-05-19T16:15:35.107 · Last modified 2026-06-17T09:34:12.560

Summary

ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedded in plaintext within the binary and used in cryptographic operations without dynamic key management. Once obtained the key can be used to decrypt CSV input files used for authenticated network scanning.

Affected products

connectwise — risk_assessment

Does this affect you?

Add your gear to cvedb and we'll alert you only when connectwise ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.