CVE-2021-36750
high · 8.1ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).
8.1
CVSS
13.5%
EPSS (exploit prob.)
96th
EPSS percentile
2021-12-22
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-307
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| zendesk | enc_datavault | < 7.2 |
| zendesk | enc_vaultapi | < 67.0 |
| sandisk | secureaccess | 3.02 |
Check a specific version with /api/v1/cve/match.
References
- https://encsecurity.zendesk.com/hc/en-us/articles/4413283717265-Update-for-ENC-Software
- https://pretalx.c3voc.de/rc3-2021-r3s/talk/QMYGR3/
- https://www.encsecurity.com/solutions.php
- https://www.westerndigital.com/en-ap/support/product-security/wdc-21014-sandisk-secureaccess-software-update
- https://encsecurity.zendesk.com/hc/en-us/articles/4413283717265-Update-for-ENC-Software
- https://pretalx.c3voc.de/rc3-2021-r3s/talk/QMYGR3/
- https://www.encsecurity.com/solutions.php
- https://www.westerndigital.com/en-ap/support/product-security/wdc-21014-sandisk-secureaccess-software-update
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-36750