216.73.216.36

CVE-2025-14823

· Published 18/12/2025 16:15 · Modified 19/12/2025 18:00

Labels: CVE-2025-14823 2025-12-187d616e1a-3288-43b1-a0dd-0a65d3e70a49CVE-2025-14823

Essential information

Published
18/12/2025 16:15
Modified
19/12/2025 18:00
Author
Creator
CVSS
5.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS metrics

Description

In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could be returned to unauthenticated users through a client-facing endpoint under certain conditions. The values remained encrypted and securely stored at rest; however, an encrypted representation could be exposed in client responses. Updating the Certificate Signing Extension to version 1.0.12 or higher ensures configuration handling occurs exclusively on the server side, preventing encrypted values from being transmitted to or rendered by client-side components.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
7d616e1a-3288-43b1-a0dd-0a65d3e70a49
NVD
View on NVD

References