PT-2021-19513 · Cyberark · Cyberark Credential Provider

Klayton Monroe

·

Published

2021-09-02

·

Updated

2022-07-12

·

CVE-2021-31796

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CyberArk Credential Provider versions prior to 12.1
Description An inadequate encryption issue may lead to Information Disclosure. An attacker may have enough information to reduce the number of possible keys for a credential file to one, or at most 2^36.
Recommendations For versions prior to 12.1, update to version 12.1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive credential files until the update is applied.

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31796

Affected Products

Cyberark Credential Provider