CVE-2021-31796
CyberArk Credential File Insufficient Effective Key Space
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may realistically have enough information that the number of possible keys (for a credential file) is only one, and the number is usually not higher than 2^36.
Una vulnerabilidad de cifrado inadecuado detectada en CyberArk Credential Provider versiones anteriores a 12.1, puede conllevar a una Divulgación de Información. Un atacante puede tener, de forma realista, suficiente información como para que el número de claves posibles (para un archivo de credenciales) sea sólo uno, y el número no suele ser superior a 2^36
CyberArk Credential Providers and possibly other Vault components use credential files to store usernames and encrypted passwords. Under certain conditions, the effective key space used to encrypt the passwords is significantly reduced. For an attacker who understands the key derivation scheme and encryption mechanics, full access to the information used to derive the encryption key is sufficient to reduce effective key space to one. With partial access, the effective key space can vary depending on the information available, and a number of those variations are unlikely to withstand brute force attacks. Versions prior to 12.1 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-04-25 CVE Reserved
- 2021-09-02 CVE Published
- 2023-02-21 First Exploit
- 2024-08-03 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/164023/CyberArk-Credential-File-Insufficient-Effective-Key-Space.html | Third Party Advisory |
|
http://seclists.org/fulldisclosure/2021/Sep/1 | Mailing List |
|
https://korelogic.com/Resources/Advisories/KL-001-2021-008.txt | Mailing List | |
https://www.cyberark.com/resources/blog | Product |
URL | Date | SRC |
---|---|---|
https://github.com/unmanarc/CACredDecoder | 2023-02-21 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cyberark Search vendor "Cyberark" | Credential Provider Search vendor "Cyberark" for product "Credential Provider" | < 12.1 Search vendor "Cyberark" for product "Credential Provider" and version " < 12.1" | - |
Affected
|