PT-2020-16764 · Robbie Van Bommel · Rvtools

Published

2020-11-05

·

Updated

2023-12-01

·

CVE-2020-27688

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions RVTools version 4.0.6
Description The issue concerns the encryption of passwords in RVTools. Specifically, the RVToolsPasswordEncryption.exe utility in RVTools 4.0.6 uses a static initialization vector (IV) and key for encryption. This static encryption can be decrypted using the Decrypt() method from the VISKD.cs file within the RVTools.exe executable. As a result, encrypted passwords used in configuration files can be decrypted, potentially exposing accounts with access to vSphere instances.
Recommendations For RVTools version 4.0.6, consider restricting access to the configuration files and the VISKD.cs file to minimize the risk of exploitation. As a temporary workaround, avoid using the RVToolsPasswordEncryption.exe utility until a secure encryption method is implemented.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27688

Affected Products

Rvtools