PT-2023-7270 · Rvtools · Rvtools
Matthias Maes
·
Published
2023-11-23
·
Updated
2023-12-01
·
CVE-2023-44303
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
RVTools versions 3.9.2 and above
Description
The issue is related to errors in cryptographic transformations, which can allow a remote attacker to gain unauthorized access to protected information. Specifically, the vulnerability in the password encryption utility and the main application can lead to the disclosure of encrypted passwords in clear text. This is caused by an incomplete fix for a previous issue.
Recommendations
For RVTools versions 3.9.2 and above, consider disabling the password encryption utility (RVToolsPasswordEncryption.exe) and restricting access to the main application (RVTools.exe) until a complete fix is available. Additionally, restrict access to stored encrypted passwords to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rvtools