First published: Thu Sep 02 2021(Updated: )
An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may realistically have enough information that the number of possible keys (for a credential file) is only one, and the number is usually not higher than 2^36.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CyberArk Credential Provider | <12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-31796.
The title of this vulnerability is 'An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure.'
The severity of CVE-2021-31796 is high with a severity value of 7.5.
The affected software is CyberArk Credential Provider version up to exclusive 12.1.
To fix this vulnerability, update CyberArk Credential Provider to version 12.1 or higher.