PT-2021-21336 · Enc · Enc Datavault

Boi Sletterink

+1

·

Published

2021-12-22

·

Updated

2022-01-06

·

CVE-2021-36750

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ENC DataVault versions prior to 7.2 VaultAPI version v67
Description The issue is related to the mishandling of key derivation, which makes it easier for attackers to determine the passwords of all DataVault users. This affects DataVault users across USB drives sold under multiple brand names.
Recommendations For ENC DataVault versions prior to 7.2, update to version 7.2 or later to resolve the issue. For VaultAPI version v67, consider disabling the use of this version until a patched version is available.

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36750

Affected Products

Enc Datavault