CVE-2020-27020: Kaspersky Password Manager

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).

Affected products

  • Kaspersky Password Manager: before 9.2 (fixed in 9.2); before 9.2.14.31 (fixed in 9.2.14.31); before 9.2.14.872 (fixed in 9.2.14.872); version 9.2 only

Published 2021-05-14. Last modified 2026-06-17.