Sensitive Data Exposure in RVTools by Dell Technologies
CVE-2023-44303
7.5HIGH
What is CVE-2023-44303?
A vulnerability in RVTools versions 3.9.2 and above allows a remote unauthenticated attacker to potentially access stored encrypted passwords due to weaknesses in the password encryption utility (RVToolsPasswordEncryption.exe) and the main application (RVTools.exe). This flaw stems from an incomplete fix of a previous vulnerability (CVE-2020-27688), potentially leading to the disclosure of sensitive information in plain text.
Affected Version(s)
RVTools Versions 3.9.2 through 4.4.5