CVE-2021-31796
02.09.2021, 01:15
An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may realistically have enough information that the number of possible keys (for a credential file) is only one, and the number is usually not higher than 2^36.Enginsight
Vendor | Product | Version |
---|---|---|
cyberark | credential_provider | 𝑥 < 12.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References