ENC DataVault 7.1.1W uses an inappropriate encryption...
Critical severity
Unreviewed
Published
Jan 3, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Jan 2, 2022
Published to the GitHub Advisory Database
Jan 3, 2022
Last updated
Jan 29, 2023
ENC DataVault 7.1.1W uses an inappropriate encryption algorithm, such that an attacker (who does not know the secret key) can make ciphertext modifications that are reflected in modified plaintext. There is no data integrity mechanism. (This behavior occurs across USB drives sold under multiple brand names.)
References