Vulnerabilities > CVE-2021-36750 - Improper Restriction of Excessive Authentication Attempts vulnerability in multiple products

047910
CVSS 5.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
zendesk
sandisk
CWE-307

Summary

ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).

Vulnerable Configurations

Part Description Count
Application
Zendesk
2
Application
Sandisk
1