{"api_version":"1","generated_at":"2026-07-23T16:54:29+00:00","cve":"CVE-2021-36750","urls":{"html":"https://cve.report/CVE-2021-36750","api":"https://cve.report/api/cve/CVE-2021-36750.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-36750","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-36750"},"summary":{"title":"CVE-2021-36750","description":"ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-12-22 14:15:00","updated_at":"2022-01-06 14:13:00"},"problem_types":["CWE-307"],"metrics":[],"references":[{"url":"https://pretalx.c3voc.de/rc3-2021-r3s/talk/QMYGR3/","name":"https://pretalx.c3voc.de/rc3-2021-r3s/talk/QMYGR3/","refsource":"MISC","tags":[],"title":"Practical bruteforce of military grade AES-1024 ::  Remote Rhein Ruhr Stage :: pretalx","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://encsecurity.zendesk.com/hc/en-us/articles/4413283717265-Update-for-ENC-Software","name":"https://encsecurity.zendesk.com/hc/en-us/articles/4413283717265-Update-for-ENC-Software","refsource":"MISC","tags":[],"title":"Update for ENC Software – ENC Security Help Center","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"https://www.westerndigital.com/en-ap/support/product-security/wdc-21014-sandisk-secureaccess-software-update","name":"https://www.westerndigital.com/en-ap/support/product-security/wdc-21014-sandisk-secureaccess-software-update","refsource":"MISC","tags":[],"title":"WDC-21014 SanDisk SecureAccess Software Update | Western Digital","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.encsecurity.com/solutions.php","name":"https://www.encsecurity.com/solutions.php","refsource":"MISC","tags":[],"title":"ENCSecurity","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-36750","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-36750","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"36750","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sandisk","cpe5":"secureaccess","cpe6":"3.02","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"36750","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zendesk","cpe5":"enc_datavault","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"36750","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zendesk","cpe5":"enc_vaultapi","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-36750","qid":"376264","title":"ENC DataVault Mishandle Key Derivation Vulnerability"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-36750","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.encsecurity.com/solutions.php","refsource":"MISC","name":"https://www.encsecurity.com/solutions.php"},{"refsource":"MISC","name":"https://encsecurity.zendesk.com/hc/en-us/articles/4413283717265-Update-for-ENC-Software","url":"https://encsecurity.zendesk.com/hc/en-us/articles/4413283717265-Update-for-ENC-Software"},{"refsource":"MISC","name":"https://www.westerndigital.com/en-ap/support/product-security/wdc-21014-sandisk-secureaccess-software-update","url":"https://www.westerndigital.com/en-ap/support/product-security/wdc-21014-sandisk-secureaccess-software-update"},{"refsource":"MISC","name":"https://pretalx.c3voc.de/rc3-2021-r3s/talk/QMYGR3/","url":"https://pretalx.c3voc.de/rc3-2021-r3s/talk/QMYGR3/"}]}},"nvd":{"publishedDate":"2021-12-22 14:15:00","lastModifiedDate":"2022-01-06 14:13:00","problem_types":["CWE-307"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zendesk:enc_vaultapi:*:*:*:*:*:*:*:*","versionEndExcluding":"67.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zendesk:enc_datavault:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sandisk:secureaccess:3.02:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"36750","Ordinal":"212308","Title":"CVE-2021-36750","CVE":"CVE-2021-36750","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"36750","Ordinal":"1","NoteData":"ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).","Type":"Description","Title":null},{"CveYear":"2021","CveId":"36750","Ordinal":"2","NoteData":"2021-12-22","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"36750","Ordinal":"3","NoteData":"2022-01-02","Type":"Other","Title":"Modified"}]}}}