CVE-2020-27020

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
14/05/2021
Last modified:
20/05/2021

Description

Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kaspersky:password_manager:*:*:*:*:*:windows:*:* 9.2 (excluding)
cpe:2.3:a:kaspersky:password_manager:*:*:*:*:*:iphone_os:*:* 9.2.14.31 (excluding)
cpe:2.3:a:kaspersky:password_manager:*:*:*:*:*:android:*:* 9.2.14.872 (excluding)
cpe:2.3:a:kaspersky:password_manager:9.2:-:*:*:*:windows:*:*