Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-27020


Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).


Published

2021-05-14T11:15:07.333

Last Modified

2024-11-21T05:20:41.337

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-326

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application kaspersky password_manager < 9.2 Yes
Application kaspersky password_manager < 9.2.14.31 Yes
Application kaspersky password_manager < 9.2.14.872 Yes
Application kaspersky password_manager 9.2 Yes

References