PT-2025-28899 · Connectwise · Connectwise Psa
Michael Newton
·
Published
2025-07-09
·
Updated
2025-08-20
·
CVE-2025-7204
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
ConnectWise PSA versions prior to 2025.9
Description:
A vulnerability exists where authenticated users could gain access to sensitive user information. Specific API requests return an overly verbose user object, which includes encrypted password hashes for other users. An attacker or privileged user could use these exposed hashes to conduct offline brute-force or dictionary attacks, potentially leading to credential compromise and privilege escalation within the system.
Recommendations:
Update ConnectWise PSA to version 2025.9 or later.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connectwise Psa