Cryptographic Implementation Flaw in Kaseya Rapid Fire Tools Network Detective
CVE-2025-32874

7.4HIGH

Key Information:

Vendor

Kaseya

Vendor
CVE Published:
16 July 2025

What is CVE-2025-32874?

A cryptographic implementation flaw has been identified in Kaseya Rapid Fire Tools Network Detective version 2.0.16.0. The vulnerability arises in the EncryptionUtil class where symmetric encryption is executed in a deterministic manner, utilizing a static salt value. This design flaw leads to predictable outputs, meaning that identical plaintext inputs result in identical ciphertext outputs, regardless of whether FIPS-compliant or non-FIPS encryption methods are used. This lack of randomness compromises the security of encrypted data, allowing potential attackers to exploit these predictable outputs and gain unauthorized access.

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.