ConnectWise Risk Assessment Hardcoded AES Decryption Key Extraction Vulnerability

Vulnerability

A vulnerability exists in the ConnectWise Password Encryption Utility within ConnectWise Risk Assessment. It allows an attacker to extract a hardcoded AES decryption key through reverse engineering. This key, embedded in plaintext in the binary, is used in cryptographic operations without proper key management. Once extracted, the key can decrypt CSV files used for authenticated network scanning.

Impact

Exploitation of this vulnerability allows for the extraction of a decryption key, which can be used to decrypt sensitive CSV input files related to network scanning.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.