PT-2021-19514 · Cyberark · Cyberark Credential Provider

Klayton Monroe

·

Published

2021-09-01

·

Updated

2023-08-08

·

CVE-2021-31797

CVSS v3.1

5.1

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CyberArk Credential Provider versions prior to 12.1
Description The user identification mechanism used by CyberArk Credential Provider is susceptible to a local host race condition, leading to password disclosure.
Recommendations For versions prior to 12.1, update to version 12.1 or later to resolve the issue. As a temporary workaround, consider implementing additional security measures to minimize the risk of password disclosure until a patch is applied.

Fix

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2021-31797

Affected Products

Cyberark Credential Provider