PT-2021-19513 · Cyberark · Cyberark Credential Provider
Klayton Monroe
·
Published
2021-09-02
·
Updated
2022-07-12
·
CVE-2021-31796
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CyberArk Credential Provider versions prior to 12.1
Description
An inadequate encryption issue may lead to Information Disclosure. An attacker may have enough information to reduce the number of possible keys for a credential file to one, or at most 2^36.
Recommendations
For versions prior to 12.1, update to version 12.1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive credential files until the update is applied.
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cyberark Credential Provider