VYPR
Vendor

ENC

Products
2
CVEs
2
Across products
3
Status
Private

Products

2

Recent CVEs

2
  • CVE-2021-36750HigDec 22, 2021
    risk 0.54cvss 8.1epss 0.14

    ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).

  • CVE-2021-36751MedJan 2, 2022
    risk 0.27cvss 4.2epss 0.00

    ENC DataVault 7.2.3 and before, and OEM versions, use an encryption algorithm that is vulnerable to data manipulation (without knowledge of the key). This is called ciphertext malleability. There is no data integrity mechanism to detect this manipulation.