CVE-2018-9842
MEDIUMCyberArk Password Vault < 9.7 - Exposure of Sensitive Information via Logon Message Replay
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2018-9842. PoCs published by Thomas Zuk, RedTeam Pentesting.
AI-analyzed exploit summary This exploit targets a memory disclosure vulnerability in CyberArk's proprietary protocol on port 1858. It sends a crafted login request to leak memory contents, writing the responses to a file for analysis.
Description
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message.
Exploits (3)
This exploit targets a memory disclosure vulnerability in CyberArk's proprietary protocol on port 1858. It sends a crafted login request to leak memory contents, writing the responses to a file for analysis.
This exploit targets a memory disclosure vulnerability in CyberArk's proprietary protocol on port 1858. It sends a crafted login request to trigger the vulnerability and dumps the server's memory response to a file.
This is a detailed advisory describing an information disclosure vulnerability in CyberArk Password Vault. The vulnerability allows an attacker to retrieve approximately 50 bytes of memory from the vault by replaying a captured logon request.
References (7)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N