CVE-2021-37151

MEDIUM
Published Sep 1, 20214y ago · Modified Jun 17, 20261w ago
5.3 CVSS 3.1
Medium
Find Similar
Published Sep 1, 2021 4y ago
Last Modified Jun 17, 2026 1w ago

Description

CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authentication policy configurations with MFA, the API response length can be used to differentiate between a valid user and an invalid one (aka Username Enumeration). Response differentiation enables attackers to enumerate usernames of valid application users. Attackers can use this information to leverage brute-force and dictionary attacks in order to discover valid account information such as passwords.

CVSS Details

Base Score
5.3
Exploitability
3.9
Impact
1.4
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity None
Availability None

Threat Intelligence

No active exploitation signals — not in CISA KEV and no EPSS score yet.

Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-203

Affected Products 1

VendorProductVersionRange
cyberarkidentity* <21.11.133

References 2

  • cyberark.com https://www.cyberark.com/products/
  • gov.il https://www.gov.il/en/departments/faq/cve_advisories

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.