Vulnerability Details CVE-2023-44303
RVTools, Version 3.9.2 and above, contain a sensitive data exposure vulnerability in the password encryption utility (RVToolsPasswordEncryption.exe) and main application (RVTools.exe). A remote unauthenticated attacker with access to stored encrypted passwords from a users' system could potentially exploit this vulnerability, leading to the disclosure of encrypted passwords in clear text. This vulnerability is caused by an incomplete fix for CVE-2020-27688.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.4%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2023-44303
-
cpe:2.3:a:robware:rvtools:3.10
-
cpe:2.3:a:robware:rvtools:3.11.6
-
cpe:2.3:a:robware:rvtools:3.11.7
-
cpe:2.3:a:robware:rvtools:3.11.8
-
cpe:2.3:a:robware:rvtools:3.11.9
-
cpe:2.3:a:robware:rvtools:3.9.2
-
cpe:2.3:a:robware:rvtools:3.9.3
-
cpe:2.3:a:robware:rvtools:3.9.5
-
cpe:2.3:a:robware:rvtools:4.0.4
-
cpe:2.3:a:robware:rvtools:4.0.6
-
cpe:2.3:a:robware:rvtools:4.0.7
-
cpe:2.3:a:robware:rvtools:4.1.2
-
cpe:2.3:a:robware:rvtools:4.1.3
-
cpe:2.3:a:robware:rvtools:4.1.4
-
cpe:2.3:a:robware:rvtools:4.2.1
-
cpe:2.3:a:robware:rvtools:4.2.2
-
cpe:2.3:a:robware:rvtools:4.3.1
-
cpe:2.3:a:robware:rvtools:4.3.2
-
cpe:2.3:a:robware:rvtools:4.4.1
-
cpe:2.3:a:robware:rvtools:4.4.2
-
cpe:2.3:a:robware:rvtools:4.4.3
-
cpe:2.3:a:robware:rvtools:4.4.4
-
cpe:2.3:a:robware:rvtools:4.4.5