CVE-2021-36751

MEDIUM

ENC DataVault < 7.2.3 - Ciphertext Malleability via Missing Integrity Check

Title source: llm
STIX 2.1

Description

ENC DataVault 7.2.3 and before, and OEM versions, use an encryption algorithm that is vulnerable to data manipulation (without knowledge of the key). This is called ciphertext malleability. There is no data integrity mechanism to detect this manipulation.

Scores

CVSS v3 4.2
EPSS 0.0049
EPSS Percentile 37.9%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-345
Status published
Products (1)
encsecurity/datavault < 7.2.3
Published Jan 02, 2022
Tracked Since Feb 18, 2026