CVE-2020-27688

RVToolsPasswordEncryption.exe in RVTools 4.0.6 allows users to encrypt passwords to be used in the configuration files. This encryption used a static IV and key, and thus using the Decrypt() method from VISKD.cs from the RVTools.exe executable allows for decrypting the encrypted passwords. The accounts used in the configuration files have access to vSphere instances.
References
Link Resource
https://www.robware.net/rvtools/ Product Vendor Advisory
https://github.com/matthiasmaes/CVE-2020-27688 Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:robware:rvtools:4.0.6:*:*:*:*:*:*:*

Information

Published : 2020-11-05 07:15

Updated : 2020-11-13 11:50


NVD link : CVE-2020-27688

Mitre link : CVE-2020-27688


JSON object : View

CWE
CWE-522

Insufficiently Protected Credentials

Advertisement

dedicated server usa

Products Affected

robware

  • rvtools