« Volver al listado

CVE-2020-27020

Estado: ModificadaAlta (7.5)—

Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-27020",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vulnerability@kaspersky.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Kaspersky Password Manager for Windows, Kaspersky Password Manager for Android, Kaspersky Password Manager for iOS",
          "versions": [
            {
              "status": "affected",
              "version": "KPM for Windows prior to 9.2 Patch F, KPM for Android prior to 9.2.14.872, KPM for iOS prior to 9.2.14.31"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-05-14T11:15:07.333",
  "references": [
    {
      "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#270421",
      "tags": [
        "Broken Link"
      ],
      "source": "vulnerability@kaspersky.com"
    },
    {
      "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#270421",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-326"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation)."
    },
    {
      "lang": "es",
      "value": "La funcionalidad password generator del programa Kaspersky Password Manager no era completamente segura desde el punto de vista criptográfico, y en algunos casos potencialmente permitía a un atacante predecir las contraseñas generadas. Un atacante necesitaría conocer información adicional (por ejemplo, el momento de la generación de la contraseña)"
    }
  ],
  "lastModified": "2026-06-17T03:08:43.963",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:kaspersky:password_manager:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13C5F5C1-31EF-4FC4-BC8B-C2DCA3151503",
              "versionEndExcluding": "9.2"
            },
            {
              "criteria": "cpe:2.3:a:kaspersky:password_manager:*:*:*:*:*:iphone_os:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A93A31B-A011-4F9C-B5E4-D191C868F04E",
              "versionEndExcluding": "9.2.14.31"
            },
            {
              "criteria": "cpe:2.3:a:kaspersky:password_manager:*:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "520B67EE-04F3-4AAB-B5F0-7C2C74EE3D28",
              "versionEndExcluding": "9.2.14.872"
            },
            {
              "criteria": "cpe:2.3:a:kaspersky:password_manager:9.2:-:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CD4A2A2-0DEE-4D14-870A-87C9E817E2DC"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vulnerability@kaspersky.com"
}