CVE-2025-7204
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/07/2025
Last modified:
10/07/2025
Description
In ConnectWise PSA versions older than 2025.9, a<br />
vulnerability exists where authenticated users could gain access to sensitive<br />
user information. Specific API requests were found to return an overly verbose<br />
user object, which included encrypted password hashes for other users.<br />
Authenticated users could then retrieve these hashes. <br />
<br />
<br />
<br />
An<br />
attacker or privileged user could then use these exposed hashes to conduct<br />
offline brute-force or dictionary attacks. Such attacks could lead to<br />
credential compromise, allowing unauthorized access to accounts, and<br />
potentially privilege escalation within the system.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM