PT-2021-19515 · Cyberark · Cyberark Credential Provider

Klayton Monroe

·

Published

2021-09-02

·

Updated

2022-07-12

·

CVE-2021-31798

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CyberArk Credential Provider versions prior to 12.1
Description The issue is related to the low entropy of the effective key space used to encrypt the cache in CyberArk Credential Provider. Under certain conditions, a local malicious user can obtain the plaintext of cache files.
Recommendations For versions prior to 12.1, update to version 12.1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31798

Affected Products

Cyberark Credential Provider