Impact
Dell RVTools versions before 4.8.1 contain an improper certificate validation weakness in the collector module. This flaw permits an attacker to tamper with or intercept communication, thereby compromising the confidentiality and integrity of data transmitted by the tool. The vulnerability is classified as CWE-295, which focuses on certificate verification failures.
Affected Systems
The affected product is Dell RVTools, specifically all releases prior to version 4.8.1. Users running older releases are at risk until they upgrade to the patched version.
Risk and Exploitability
The CVSS base score of 6.8 indicates a moderate severity. The EPSS score is not available, so the current exploit likelihood is uncertain, and the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector is remote and does not require authentication, meaning an adversary can potentially target the collector component from an external network.
OpenCVE Enrichment