CVE-2021-36750: High severity zendesk enc datavault vulnerability
ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-36750?
CVE-2021-36750 is a vulnerability in ENC DataVault before 7.2 and VaultAPI v67 that mishandles key derivation, making it easier for attackers to determine the passwords of all DataVault users.
How does CVE-2021-36750 impact Zendesk Enc DataVault?
CVE-2021-36750 affects Zendesk Enc DataVault versions up to exclusive 7.2.
How does CVE-2021-36750 impact Zendesk Enc VaultAPI?
CVE-2021-36750 affects Zendesk Enc VaultAPI versions up to exclusive 67.0.
How does CVE-2021-36750 impact Sandisk Secureaccess?
CVE-2021-36750 affects Sandisk Secureaccess version 3.02.
What is the severity of CVE-2021-36750?
CVE-2021-36750 has a severity level of 8.1 (high).
What is the CWE of CVE-2021-36750?
CVE-2021-36750 is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts).
How can I update ENC Software to address CVE-2021-36750?
To address CVE-2021-36750, please follow the instructions provided in the [ENC Software update article](https://encsecurity.zendesk.com/hc/en-us/articles/4413283717265-Update-for-ENC-Software).
Where can I find more information about CVE-2021-36750?
You can find more information about CVE-2021-36750 in the following resources: [RC3 2021 Talk](https://pretalx.c3voc.de/rc3-2021-r3s/talk/QMYGR3/) and [ENC Security Solutions](https://www.encsecurity.com/solutions.php).