CyberArk Credential File Insufficient Effective Key Space

Discussion in 'News Aggregator' started by Packet Storm, 3 Sep 2021.

  1. Packet Storm

    Packet Storm Guest

    CyberArk Credential Providers and possibly other Vault components use credential files to store usernames and encrypted passwords. Under certain conditions, the effective key space used to encrypt the passwords is significantly reduced. For an attacker who understands the key derivation scheme and encryption mechanics, full access to the information used to derive the encryption key is sufficient to reduce effective key space to one. With partial access, the effective key space can vary depending on the information available, and a number of those variations are unlikely to withstand brute force attacks. Versions prior to 12.1 are affected.

    Continue reading...
     

Share This Page

Loading...