PT-2025-28294 · Guixt · Guixt
Published
2025-07-08
·
Updated
2025-07-08
·
CVE-2025-42979
CVSS v3.1
5.6
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
GuiXT (affected versions not specified)
Description:
The issue concerns the use of obfuscation algorithms instead of secure symmetric ciphers for storing RFC user credentials on the client PC. This leads to a high impact on confidentiality, as an attacker gaining access to the user hive of the Windows registry could recreate the original password. There is no impact on the integrity or availability of the application.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Guixt