CVE-2025-7204

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/07/2025
Last modified:
20/08/2025

Description

In ConnectWise PSA versions older than 2025.9, a<br /> vulnerability exists where authenticated users could gain access to sensitive<br /> user information. Specific API requests were found to return an overly verbose<br /> user object, which included encrypted password hashes for other users.<br /> Authenticated users could then retrieve these hashes. <br /> <br /> <br /> <br /> An<br /> attacker or privileged user could then use these exposed hashes to conduct<br /> offline brute-force or dictionary attacks. Such attacks could lead to<br /> credential compromise, allowing unauthorized access to accounts, and<br /> potentially privilege escalation within the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:connectwise:professional_service_automation:*:*:*:*:*:*:*:* 2025.9 (excluding)