
Cloud Vulnerability DB
A community-led vulnerabilities database
RVTools versions 3.9.2 through 4.4.5 contain a sensitive data exposure vulnerability in the password encryption utility (RVToolsPasswordEncryption.exe) and main application (RVTools.exe). This vulnerability (CVE-2023-44303) was disclosed on November 23, 2023, and is an incomplete fix for a previous vulnerability (CVE-2020-27688) (Dell Advisory).
The vulnerability has been assigned a CVSS v3.1 Base Score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The weakness is categorized under CWE-522 (Insufficiently Protected Credentials) and CWE-310 (Cryptographic Issues) (Dell Advisory, NVD).
A remote unauthenticated attacker with access to stored encrypted passwords from a users' system could potentially exploit this vulnerability, leading to the disclosure of encrypted passwords in clear text (Dell Advisory).
Dell has released version 4.5.0 as a remediation for this vulnerability. For users who wish to stay on an affected version, Dell recommends utilizing pass-through authentication. Instructions for this mechanism can be found in the RVTools PDF documentation (Dell Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."