2021-10-11 05:00:54 +00:00
{
"data_type" : "CVE" ,
"data_format" : "MITRE" ,
"data_version" : "4.0" ,
"CVE_data_meta" : {
"ID" : "CVE-2021-42138" ,
2021-12-16 09:54:07 +01:00
"ASSIGNER" : "psirt@thalesgroup.com" ,
2021-12-14 19:24:27 +01:00
"STATE" : "PUBLIC"
2021-10-11 05:00:54 +00:00
} ,
2021-12-14 19:24:27 +01:00
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "Safenet Authentication Service" ,
"version" : {
"version_data" : [
{
"version_affected" : "<" ,
"version_name" : "Windows Logon Agent" ,
"version_value" : "3.4.4"
}
]
}
}
]
} ,
"vendor_name" : "Thales CPL"
}
]
}
} ,
"credit" : [
{
"lang" : "eng" ,
"value" : "compass-security"
}
] ,
2021-10-11 05:00:54 +00:00
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2021-12-14 19:24:27 +01:00
"value" : "A user of a machine protected by SafeNet Agent for Windows Logon may leverage weak entropy to access the encrypted credentials of any or all the users on that machine."
}
]
} ,
"generator" : {
"engine" : "Vulnogram 0.0.9"
} ,
"impact" : {
"cvss" : {
"attackComplexity" : "HIGH" ,
"attackVector" : "LOCAL" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 7.2 ,
"baseSeverity" : "HIGH" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"privilegesRequired" : "LOW" ,
"scope" : "CHANGED" ,
"userInteraction" : "REQUIRED" ,
"vectorString" : "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N" ,
"version" : "3.1"
}
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "https://cwe.mitre.org/data/definitions/336.html"
}
]
2021-10-11 05:00:54 +00:00
}
]
2021-12-14 19:24:27 +01:00
} ,
"references" : {
"reference_data" : [
{
2021-12-20 21:01:10 +00:00
"refsource" : "MISC" ,
"url" : "https://supportportal.gemalto.com/csm?sys_kb_id=a52bd13adbff7010f0e322080596194a&id=kb_article_view&sysparm_rank=1&sysparm_tsqueryId=b3bdd932db33b010f0e3220805961955" ,
"name" : "https://supportportal.gemalto.com/csm?sys_kb_id=a52bd13adbff7010f0e322080596194a&id=kb_article_view&sysparm_rank=1&sysparm_tsqueryId=b3bdd932db33b010f0e3220805961955"
2021-12-14 19:24:27 +01:00
} ,
{
2021-12-20 21:01:10 +00:00
"refsource" : "MISC" ,
"url" : "https://supportportal.gemalto.com/csm?sys_kb_id=e8397662dbb7fc10520c4705059619eb&id=kb_article_view&sysparm_rank=2&sysparm_tsqueryId=b3bdd932db33b010f0e3220805961955" ,
"name" : "https://supportportal.gemalto.com/csm?sys_kb_id=e8397662dbb7fc10520c4705059619eb&id=kb_article_view&sysparm_rank=2&sysparm_tsqueryId=b3bdd932db33b010f0e3220805961955"
2021-12-14 19:24:27 +01:00
} ,
{
2021-12-20 21:01:10 +00:00
"refsource" : "MISC" ,
"url" : "https://cpl.thalesgroup.com/support/security-updates" ,
"name" : "https://cpl.thalesgroup.com/support/security-updates"
2021-12-14 19:24:27 +01:00
}
]
} ,
"source" : {
"discovery" : "EXTERNAL"
2021-10-11 05:00:54 +00:00
}
2021-12-20 21:01:10 +00:00
}