Vulnerability Description
In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The secret does not differ between the tested versions and different operating systems.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Stimulsoft | Designer | 2023.1.4 |
Related Weaknesses (CWE)
References
- http://stimulsoft.comProduct
- https://cloud-trustit.spp.at/s/Db8ZfNq2WYiNCHaBroken Link
- https://cves.at/posts/cve-2023-25263/writeup/ExploitThird Party Advisory
- http://stimulsoft.comProduct
- https://cloud-trustit.spp.at/s/Db8ZfNq2WYiNCHaBroken Link
- https://cves.at/posts/cve-2023-25263/writeup/ExploitThird Party Advisory
FAQ
What is CVE-2023-25263?
CVE-2023-25263 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static ...
How severe is CVE-2023-25263?
CVE-2023-25263 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-25263?
Check the references section above for vendor advisories and patch information. Affected products include: Stimulsoft Designer.