CVE-2025-5353: High severity Ivanti Workspace Control vulnerability
Published Jun 10, 2025
·Updated
A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials.
Affected Software
2 affected components
Ivanti Workspace Control<10.19.10.0
Ivanti Workspace Control<10.19.10.0
Event History
Jun 10, 2025
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
News Published
via BleepingComputer·03:22 PM
News Published
via BleepingComputer·03:23 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-5353?
CVE-2025-5353 has been classified as a high severity vulnerability due to its potential for exposing sensitive SQL credentials.
2
How do I fix CVE-2025-5353?
To fix CVE-2025-5353, upgrade Ivanti Workspace Control to version 10.19.10.0 or later.
3
Who is affected by CVE-2025-5353?
CVE-2025-5353 affects local authenticated users of Ivanti Workspace Control versions prior to 10.19.10.0.
4
What type of attack does CVE-2025-5353 enable?
CVE-2025-5353 enables local authenticated attackers to decrypt stored SQL credentials due to a hardcoded key.
5
What products are involved in CVE-2025-5353?
CVE-2025-5353 specifically involves Ivanti Workspace Control software versions before 10.19.10.0.