Vulnerabilities > CVE-2021-36750 - Improper Restriction of Excessive Authentication Attempts vulnerability in multiple products

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
zendesk
sandisk
CWE-307

Summary

ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).

Vulnerable Configurations

Part Description Count
Application
Zendesk
2
Application
Sandisk
1