PT-2025-28294 · Guixt · Guixt

Published

2025-07-08

·

Updated

2025-07-08

·

CVE-2025-42979

CVSS v3.1

5.6

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GuiXT (affected versions not specified)
Description: The issue concerns the use of obfuscation algorithms instead of secure symmetric ciphers for storing RFC user credentials on the client PC. This leads to a high impact on confidentiality, as an attacker gaining access to the user hive of the Windows registry could recreate the original password. There is no impact on the integrity or availability of the application.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-16215
CVE-2025-42979

Affected Products

Guixt