CVE-2021-36750
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD
Description
ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).
Affected (3)
Products: Zendesk: Enc Datavault, Enc Vaultapi · Sandisk: Secureaccess
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.2 | |
| Before 67.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.02 |
References (8)
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.