Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mpq4-x452-vvrx

Опубликовано: 24 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

RVTools, Version 3.9.2 and above, contain a sensitive data exposure vulnerability in the password encryption utility (RVToolsPasswordEncryption.exe) and main application (RVTools.exe). A remote unauthenticated attacker with access to stored encrypted passwords from a users' system could potentially exploit this vulnerability, leading to the disclosure of encrypted passwords in clear text. This vulnerability is caused by an incomplete fix for CVE-2020-27688.

RVTools, Version 3.9.2 and above, contain a sensitive data exposure vulnerability in the password encryption utility (RVToolsPasswordEncryption.exe) and main application (RVTools.exe). A remote unauthenticated attacker with access to stored encrypted passwords from a users' system could potentially exploit this vulnerability, leading to the disclosure of encrypted passwords in clear text. This vulnerability is caused by an incomplete fix for CVE-2020-27688.

EPSS

Процентиль: 24%
0.00084
Низкий

7.5 High

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

RVTools, Version 3.9.2 and above, contain a sensitive data exposure vulnerability in the password encryption utility (RVToolsPasswordEncryption.exe) and main application (RVTools.exe). A remote unauthenticated attacker with access to stored encrypted passwords from a users' system could potentially exploit this vulnerability, leading to the disclosure of encrypted passwords in clear text. This vulnerability is caused by an incomplete fix for CVE-2020-27688.

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость приложения аудита виртуализации RVTools, связанная с ошибками криптографических преобразований, позволяющая получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 24%
0.00084
Низкий

7.5 High

CVSS3

Дефекты

CWE-522