Описание
ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).
Ссылки
- Vendor Advisory
- Third Party Advisory
- Product
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
- Product
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.2 (исключая)Версия до 67.0 (исключая)
Одно из
cpe:2.3:a:zendesk:enc_datavault:*:*:*:*:*:*:*:*
cpe:2.3:a:zendesk:enc_vaultapi:*:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:sandisk:secureaccess:3.02:*:*:*:*:*:*:*
EPSS
Процентиль: 95%
0.19701
Средний
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-307
Связанные уязвимости
github
около 4 лет назад
ENC DataVault 7.1.1W and VaultAPI v67, which is currently being used in various other applications, mishandles key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).
EPSS
Процентиль: 95%
0.19701
Средний
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-307