CVE-2025-48748: Critical severity netwrix directory manager vulnerability
Published May 29, 2025
·Updated
Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.
Affected Software
2 affected components
Netwrix Directory Manager<=10.0.7784.0
Netwrix Directory Manager<=10.0.7784.0
Event History
May 29, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48748?
CVE-2025-48748 has been classified as a high severity vulnerability due to the presence of a hard-coded password in the software.
2
How do I fix CVE-2025-48748?
To mitigate CVE-2025-48748, upgrade to a version of Netwrix Directory Manager later than 10.0.7784.0 where the hard-coded password is removed.
3
What software is affected by CVE-2025-48748?
CVE-2025-48748 affects Netwrix Directory Manager versions up to and including 10.0.7784.0.
4
What is the risk of CVE-2025-48748?
The risk of CVE-2025-48748 includes unauthorized access to the system due to the exposure of a hard-coded password.
5
Is there any workaround for CVE-2025-48748?
Currently, the recommended action for CVE-2025-48748 is to update to a patched version, as there are no effective workarounds available.