Description
A user of a machine protected by SafeNet Agent for Windows Logon may leverage weak entropy to access the encrypted credentials of any or all the users on that machine.
References (3)
Core 3
Core References
Permissions Required x_refsource_misc
https://supportportal.gemalto.com/csm?sys_kb_id=a52bd13adbff7010f0e322080596194a&id=kb_article_view&sysparm_rank=1&sysparm_tsqueryId=b3bdd932db33b010f0e3220805961955
Permissions Required x_refsource_misc
https://supportportal.gemalto.com/csm?sys_kb_id=e8397662dbb7fc10520c4705059619eb&id=kb_article_view&sysparm_rank=2&sysparm_tsqueryId=b3bdd932db33b010f0e3220805961955
Vendor Advisory x_refsource_misc
https://cpl.thalesgroup.com/support/security-updates
Scores
CVSS v3
7.2
EPSS
0.0058
EPSS Percentile
43.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Details
CWE
CWE-331
Status
published
Products (1)
thalesgroup/safenet_windows_logon_agent
< 3.4.4
Published
Dec 20, 2021
Tracked Since
Feb 18, 2026