CVE-2020-27688

RVToolsPasswordEncryption.exe in RVTools 4.0.6 allows users to encrypt passwords to be used in the configuration files. This encryption used a static IV and key, and thus using the Decrypt() method from VISKD.cs from the RVTools.exe executable allows for decrypting the encrypted passwords. The accounts used in the configuration files have access to vSphere instances.
References
Link Resource
https://www.robware.net/rvtools/ Product Vendor Advisory
https://github.com/matthiasmaes/CVE-2020-27688 Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:robware:rvtools:4.0.6:*:*:*:*:*:*:*

Information

Published : 2020-11-05 03:15

Updated : 2020-11-13 07:50


NVD link : CVE-2020-27688

Mitre link : CVE-2020-27688

Products Affected
No products.
CWE