- Description
- Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).
- Source
- vulnerability@kaspersky.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
- nvd@nist.gov
- CWE-326
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:kaspersky:password_manager:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "13C5F5C1-31EF-4FC4-BC8B-C2DCA3151503",
"versionEndExcluding": "9.2"
},
{
"criteria": "cpe:2.3:a:kaspersky:password_manager:*:*:*:*:*:iphone_os:*:*",
"vulnerable": true,
"matchCriteriaId": "8A93A31B-A011-4F9C-B5E4-D191C868F04E",
"versionEndExcluding": "9.2.14.31"
},
{
"criteria": "cpe:2.3:a:kaspersky:password_manager:*:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "520B67EE-04F3-4AAB-B5F0-7C2C74EE3D28",
"versionEndExcluding": "9.2.14.872"
},
{
"criteria": "cpe:2.3:a:kaspersky:password_manager:9.2:-:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "1CD4A2A2-0DEE-4D14-870A-87C9E817E2DC"
}
],
"operator": "OR"
}
]
}
]