PT-2021-3158 · Kaspersky · Kaspersky Password Manager

Jibee

·

Published

2021-04-20

·

Updated

2021-08-08

·

CVE-2020-27020

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kaspersky Password Manager (affected versions not specified)
Description The password generator feature in Kaspersky Password Manager was not completely cryptographically strong, potentially allowing an attacker to predict generated passwords in some cases. An attacker would need to know some additional information, such as the time of password generation. The implementation used a pseudorandom number generator (PRNG) that generated passwords based on the current system time in seconds, resulting in the same password being generated by every instance of KPM at the same second. It is estimated that KPM could generate around 31.5 million passwords in a year, which could be brute-forced in minutes, especially if the attacker knows the approximate time of account creation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02828
CVE-2020-27020

Affected Products

Kaspersky Password Manager