CVE-2021-42138

HIGH

SafeNet Agent for Windows Logon - Info Disclosure

Title source: llm
STIX 2.1

Description

A user of a machine protected by SafeNet Agent for Windows Logon may leverage weak entropy to access the encrypted credentials of any or all the users on that machine.

Scores

CVSS v3 7.2
EPSS 0.0019
EPSS Percentile 40.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

Details

CWE
CWE-331
Status published
Products (1)
thalesgroup/safenet_windows_logon_agent < 3.4.4
Published Dec 20, 2021
Tracked Since Feb 18, 2026