CVE-2021-36751
Summary
| CVE | CVE-2021-36751 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-02 16:15:00 UTC |
| Updated | 2022-12-13 19:30:00 UTC |
| Description | ENC DataVault 7.2.3 and before, and OEM versions, use an encryption algorithm that is vulnerable to data manipulation (without knowledge of the key). This is called ciphertext malleability. There is no data integrity mechanism to detect this manipulation. |
Risk And Classification
Problem Types: CWE-345
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Encsecurity | Datavault | All | All | All | All |
| Application | Encsecurity | Datavault | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security check | MISC | encsecurity.zendesk.com | |
| Practical bruteforce of military grade AES-1024 :: Remote Rhein Ruhr Stage :: pretalx | MISC | pretalx.c3voc.de | |
| Update for ENC Software – ENC Security Help Center | MISC | encsecurity.zendesk.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.