Vulnerability Description
The user identification mechanism used by CyberArk Credential Provider prior to 12.1 is susceptible to a local host race condition, leading to password disclosure.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cyberark | Credential Provider | < 12.1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/164033/CyberArk-Credential-Provider-Race-CoThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Sep/2Mailing ListThird Party Advisory
- https://korelogic.com/Resources/Advisories/KL-001-2021-009.txtMailing ListThird Party Advisory
- https://www.cyberark.com/resources/blogProduct
- http://packetstormsecurity.com/files/164033/CyberArk-Credential-Provider-Race-CoThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Sep/2Mailing ListThird Party Advisory
- https://korelogic.com/Resources/Advisories/KL-001-2021-009.txtMailing ListThird Party Advisory
- https://www.cyberark.com/resources/blogProduct
FAQ
What is CVE-2021-31797?
CVE-2021-31797 is a vulnerability with a CVSS score of 5.1 (MEDIUM). The user identification mechanism used by CyberArk Credential Provider prior to 12.1 is susceptible to a local host race condition, leading to password disclosure.
How severe is CVE-2021-31797?
CVE-2021-31797 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-31797?
Check the references section above for vendor advisories and patch information. Affected products include: Cyberark Credential Provider.