In ConnectWise PSA versions older than 2025.9, a vulnerability exists where authenticated users could gain access to sensitive user information. Specific API requests were found to return an overly verbose user object, which included encrypted password hashes for other users. Authenticated users could then retrieve these hashes.  An attacker or privileged user could then use these exposed hashes to conduct offline brute-force or dictionary attacks. Such attacks could lead to credential compromise, allowing unauthorized access to accounts, and potentially privilege escalation within the system.
History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00036}

epss

{'score': 0.00041}


Thu, 10 Jul 2025 11:45:00 +0000

Type Values Removed Values Added
References

Wed, 09 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Jul 2025 15:00:00 +0000

Type Values Removed Values Added
Description In ConnectWise PSA versions older than 2025.9, a vulnerability exists where authenticated users could gain access to sensitive user information. Specific API requests were found to return an overly verbose user object, which included encrypted password hashes for other users. Authenticated users could then retrieve these hashes.  An attacker or privileged user could then use these exposed hashes to conduct offline brute-force or dictionary attacks. Such attacks could lead to credential compromise, allowing unauthorized access to accounts, and potentially privilege escalation within the system.
Title Exposure of password hashes via API responses in ConnectWise PSA
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ConnectWise

Published:

Updated: 2025-07-10T11:35:40.506Z

Reserved: 2025-07-07T11:30:08.002Z

Link: CVE-2025-7204

cve-icon Vulnrichment

Updated: 2025-07-09T15:57:31.541Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-09T15:15:25.283

Modified: 2025-07-10T13:17:30.017

Link: CVE-2025-7204

cve-icon Redhat

No data.