CVE-2025-4876: Hardcoded Key Revealed in ConnectWise Password Encryption Utility
ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedded in plaintext within the binary and used in cryptographic operations without dynamic key management. Once obtained the key can be used to decrypt CSV input files used for authenticated network scanning.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4876?
CVE-2025-4876 has a high severity due to the potential for an attacker to extract sensitive encryption keys.
How do I fix CVE-2025-4876?
To mitigate CVE-2025-4876, update the ConnectWise Password Encryption Utility to the latest version that addresses this vulnerability.
What versions of ConnectWise Password Encryption Utility are affected by CVE-2025-4876?
All versions of the ConnectWise Password Encryption Utility that contain the hardcoded AES decryption key are affected by CVE-2025-4876.
What kind of attack is possible with CVE-2025-4876?
An attacker can perform a reverse engineering attack to extract the hardcoded AES decryption key embedded in the binary.
Is there a workaround for CVE-2025-4876?
Currently, the best approach is to avoid using the affected version of the ConnectWise Password Encryption Utility until a patch is available.