CVE-2021-36750 Information
Jun 07, 2022
cve
Description
ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Reference
https://www.encsecurity.com/solutions.php https://encsecurity.zendesk.com/hc/en-us/articles/4413283717265-Update-for-ENC-Software https://www.westerndigital.com/en-ap/support/product-security/wdc-21014-sandisk-secureaccess-software-update https://pretalx.c3voc.de/rc3-2021-r3s/talk/QMYGR3/
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
8.1
Share on: