CVE-2021-31798

Severity CVSS v4.0:
Pending analysis
Type:
CWE-331 Insufficient Entropy
Publication date:
02/09/2021
Last modified:
12/07/2022

Description

The effective key space used to encrypt the cache in CyberArk Credential Provider prior to 12.1 has low entropy, and under certain conditions a local malicious user can obtain the plaintext of cache files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cyberark:credential_provider:*:*:*:*:*:*:*:* 12.1 (excluding)