cve/2020/CVE-2020-27020.md

19 lines
1016 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2020-27020](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27020)
![](https://img.shields.io/static/v1?label=Product&message=Kaspersky%20Password%20Manager%20for%20Windows%2C%20Kaspersky%20Password%20Manager%20for%20Android%2C%20Kaspersky%20Password%20Manager%20for%20iOS&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Information%20Disclosure&color=brighgreen)
### Description
Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).
### POC
#### Reference
- https://support.kaspersky.com/general/vulnerability.aspx?el=12430#270421
2024-06-09 00:33:16 +00:00
- https://support.kaspersky.com/general/vulnerability.aspx?el=12430#270421
2024-05-25 21:48:12 +02:00
#### Github
No PoCs found on GitHub currently.