CVE-2025-48748 Details
Description
Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.
A hard-coded password vulnerability has been identified in Netwrix Directory Manager (formerly Imanami GroupID) in versions through 10.0.7784.0. This vulnerability allows authentication as an administrator to the Windows server hosting Netwrix Directory Manager or to the application itself. Although the hard-coded password was removed in version 9, it remains in the installer and can be used by customers who upgraded from earlier versions.
Netwrix advises customers to update to the latest release of version 10 if they are using a version earlier than 10.0.7784.0. For those running version 10.0.7784.0 or earlier, it is recommended to check the Microsoft Internet Information Services (IIS) Application Pools for the 'GroupIDSSUser' as the Application Pool Identity. If this user is being used, customers should create a new service account, update the Application Pool Identity, and then delete the 'GroupIDSSUser' account. Netwrix has published a utility to assist with this assessment and remediation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.netwrix.com/t/adv-2025-013-hard-coded-password-in-netwrix-directory-manager-formerly-imanami-groupid-v10-and-earlier/13945 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| netwrix directory manager | <= 10.0.7784.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2025 | Initial Analysis | [email protected] |
| May 29, 2025 | CVE Modified | CISA-ADP |
| May 29, 2025 | New CVE Received | [email protected] |