PT-2021-3158 · Kaspersky · Kaspersky Password Manager
Jibee
·
Published
2021-04-20
·
Updated
2021-08-08
·
CVE-2020-27020
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kaspersky Password Manager (affected versions not specified)
Description
The password generator feature in Kaspersky Password Manager was not completely cryptographically strong, potentially allowing an attacker to predict generated passwords in some cases. An attacker would need to know some additional information, such as the time of password generation. The implementation used a pseudorandom number generator (PRNG) that generated passwords based on the current system time in seconds, resulting in the same password being generated by every instance of KPM at the same second. It is estimated that KPM could generate around 31.5 million passwords in a year, which could be brute-forced in minutes, especially if the attacker knows the approximate time of account creation.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kaspersky Password Manager