CVE-2025-54394

MEDIUM

Netwrix Directory Manager - Insufficiently Protected Credentials

Title source: rule
STIX 2.1

Description

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources.

Scores

CVSS v3 5.3
EPSS 0.0006
EPSS Percentile 18.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-522
Status published
Products (1)
netwrix/directory_manager 11.0.0.0 - 11.1.25162.02
Published Aug 07, 2025
Tracked Since Feb 18, 2026