Race Condition Vulnerability in CyberArk Credential Provider
CVE-2021-31797

5.1MEDIUM

Key Information:

Vendor

Cyberark

Vendor
CVE Published:
2 September 2021

What is CVE-2021-31797?

A race condition vulnerability exists in CyberArk Credential Provider prior to version 12.1, enabling a local host attacker to exploit the user identification mechanism. This vulnerability could lead to password disclosure, compromising the security of sensitive credentials. Organizations using affected versions should consider applying security updates to mitigate potential risks associated with unauthorized access.

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.