PT-2025-28963 · Undefined · Undefined

Cody Kretsinger

·

Published

2025-07-09

·

Updated

2025-11-24

·

CVE-2025-32874

CVSS v3.1

7.5

High

VectorAV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kaseya Rapid Fire Tools Network Detective versions through 2.0.16.0
Description A cryptographic implementation flaw exists in the password encryption mechanism within the EncryptionUtil class. Symmetric encryption is implemented in a deterministic and non-randomized fashion, deriving both the encryption key and the Initialization Vector (IV) from a fixed, hardcoded input using a static salt value. Identical plaintext inputs consistently produce identical ciphertext outputs, regardless of whether FIPS or non-FIPS encryption methods are used. This predictability and reversibility stem from the lack of per-operation randomness and encryption authentication.
Recommendations Versions prior to 2.0.16.0 should be used.

Fix

Missing Encryption of Sensitive Data

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2025-32874

Affected Products

Undefined