Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-31796

Опубликовано: 02 сент. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may realistically have enough information that the number of possible keys (for a credential file) is only one, and the number is usually not higher than 2^36.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cyberark:credential_provider:*:*:*:*:*:*:*:*
Версия до 12.1 (исключая)

EPSS

Процентиль: 69%
0.00609
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may realistically have enough information that the number of possible keys (for a credential file) is only one, and the number is usually not higher than 2^36.

EPSS

Процентиль: 69%
0.00609
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-327