Description
An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may realistically have enough information that the number of possible keys (for a credential file) is only one, and the number is usually not higher than 2^36.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-18677 | An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may realistically have enough information that the number of possible keys (for a credential file) is only one, and the number is usually not higher than 2^36. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T23:10:30.651Z
Reserved: 2021-04-25T00:00:00.000Z
Link: CVE-2021-31796
No data.
Status : Modified
Published: 2021-09-02T01:15:06.400
Modified: 2024-11-21T06:06:14.343
Link: CVE-2021-31796
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD