Vulnerability CVE-2021-31798


Published: 2021-09-02

Description:
The effective key space used to encrypt the cache in CyberArk Credential Provider prior to 12.1 has low entropy, and under certain conditions a local malicious user can obtain the plaintext of cache files.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
CyberArk Credential Provider Local Cache Decryption
Klayton Monroe
04.09.2021

Type:

CWE-326

(Inadequate Encryption Strength)

 References:
https://www.cyberark.com/resources/blog
http://seclists.org/fulldisclosure/2021/Sep/3
https://korelogic.com/Resources/Advisories/KL-001-2021-010.txt

Copyright 2024, cxsecurity.com

 

Back to Top