← All CVEs

CVE-2021-36750

high · 8.1

ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).

8.1
CVSS
13.5%
EPSS (exploit prob.)
96th
EPSS percentile
2021-12-22
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-307

Affected products

VendorProductAffected versions
zendeskenc_datavault< 7.2
zendeskenc_vaultapi< 67.0
sandisksecureaccess3.02

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-36750