CVE-2021-31796: High severity cyberark credential provider vulnerability
Published Sep 2, 2021
·Updated
An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may realistically have enough information that the number of possible keys (for a credential file) is only one, and the number is usually not higher than 2^36.
Affected Software
1 affected component
CyberArk Credential Provider<12.1
Event History
Sep 2, 2021
CVE Published
via MITRE·12:24 AM
Data Sourced
via MITRE·12:24 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this cybersecurity vulnerability?
The vulnerability ID is CVE-2021-31796.
2
What is the title of this vulnerability?
The title of this vulnerability is 'An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure.'
3
What is the severity of CVE-2021-31796?
The severity of CVE-2021-31796 is high with a severity value of 7.5.
4
What is the affected software for CVE-2021-31796?
The affected software is CyberArk Credential Provider version up to exclusive 12.1.
5
How can this vulnerability be fixed?
To fix this vulnerability, update CyberArk Credential Provider to version 12.1 or higher.