Weak Entropy in SafeNet Agent for Windows Logon Exposes User Credentials
CVE-2021-42138

7.2HIGH

Key Information:

Vendor

Thales Cpl

Vendor
CVE Published:
20 December 2021

What is CVE-2021-42138?

The SafeNet Agent for Windows Logon is susceptible to a vulnerability where weak entropy can be exploited by local users. This weakness enables unauthorized access to the encrypted credentials of any user on the affected system. If successfully exploited, an attacker could compromise user accounts and sensitive data, highlighting the importance of implementing strong entropy measures to secure credential storage effectively.

Affected Version(s)

Safenet Authentication Service Windows Logon Agent < 3.4.4

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

compass-security
.