ZeroHour

CVE-2021-36751

CVSS 3.1
4.2 medium
EPSS
<1%p40
Published
()
Modified
Description

ENC DataVault 7.2.3 and before, and OEM versions, use an encryption algorithm that is vulnerable to data manipulation (without knowledge of the key). This is called ciphertext malleability. There is no data integrity mechanism to detect this manipulation.

Vendors
encsecurity
Products
datavault
Weakness
CWE-345
Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news