← Zuruck zu CVEs
CVE-2021-36750
HIGH8.1
Beschreibung
ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).
CVE Details
CVSS v3.1 Bewertung8.1
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht12/22/2021
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
sandisk:secureaccesszendesk:enc_datavaultzendesk:enc_vaultapi
Schwachen (CWE)
CWE-307
Referenzen
https://encsecurity.zendesk.com/hc/en-us/articles/4413283717265-Update-for-ENC-Software(cve@mitre.org)
https://pretalx.c3voc.de/rc3-2021-r3s/talk/QMYGR3/(cve@mitre.org)
https://www.encsecurity.com/solutions.php(cve@mitre.org)
https://www.westerndigital.com/en-ap/support/product-security/wdc-21014-sandisk-secureaccess-software-update(cve@mitre.org)
https://encsecurity.zendesk.com/hc/en-us/articles/4413283717265-Update-for-ENC-Software(af854a3a-2127-422b-91ae-364da2661108)
https://pretalx.c3voc.de/rc3-2021-r3s/talk/QMYGR3/(af854a3a-2127-422b-91ae-364da2661108)
https://www.encsecurity.com/solutions.php(af854a3a-2127-422b-91ae-364da2661108)
https://www.westerndigital.com/en-ap/support/product-security/wdc-21014-sandisk-secureaccess-software-update(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.