CVE Feed

    Dashboard / CVE / CVE-2020-27688

    CVE-2020-27688

    RVToolsPasswordEncryption.exe in RVTools 4.0.6 allows users to encrypt passwords to be used in the configuration files. This encryption used a static IV and key, and thus using the Decrypt() method from VISKD.cs from the RVTools.exe executable allows for decrypting the encrypted passwords. The accounts used in the configuration files have access to vSphere instances.

    Published:Nov 5, 2020
    Last Modified:Nov 21, 2024
    EPS:Nov 5, 2020
    EPSS Score:0.08027
    CVSS Score:7.5

    Affected Products

    Vendor
    Robware
    Product
    Rvtools

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High