CVE-2021-36750
HIGH 8.1EPSS 13.5%
ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).
- CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N - CVSS v2.0
- 5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N - EPSS
- 13.53% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2021-12-22
- Updated
- 2024-08-04
Proof-of-concept exploits (1)
- mamba-4-ever/CVE-2021-367500★ · 2021-10-14