The effective key space used to encrypt the cache in CyberArk Credential Provider prior to 12.1 has low entropy, and under certain conditions a local malicious user can obtain the plaintext of cache files.
2021-09-02T01:15:06.447
2024-11-21T06:06:14.727
Modified
CVSSv3.1: 4.4 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:N/A:N
3.4
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cyberark | credential_provider | < 12.1 | Yes |