VulnerabilityModified
CVE-2023-25263
In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used.
MEDIUM 5.5EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The secret does not differ between the tested versions and different operating systems.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-312
- Affected
- stimulsoft/designer
- Source
- cve@mitre.org
References
- https://cloud-trustit.spp.at/s/Db8ZfNq2WYiNCHaBroken Link
- https://cves.at/posts/cve-2023-25263/writeup/Exploit, Third Party Advisory
- https://cloud-trustit.spp.at/s/Db8ZfNq2WYiNCHaBroken Link
- https://cves.at/posts/cve-2023-25263/writeup/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.