Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program.
References
Link | Resource |
---|---|
https://www.ironkey.com/usb-flash-drive-flaw-exposed | Broken Link |
http://it.slashdot.org/story/10/01/05/1734242/ | Third Party Advisory |
http://securitytracker.com/id?1023409 | Third Party Advisory VDB Entry |
http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html | Third Party Advisory |
http://blogs.zdnet.com/hardware/?p=6655 | Not Applicable |
http://www.verbatim.com/security/security-update.cfm | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2010-01-07 11:30
Updated : 2017-11-22 09:16
NVD link : CVE-2010-0227
Mitre link : CVE-2010-0227
JSON object : View
CWE
CWE-255
Credentials Management Errors
Products Affected
verbatim
- corporate_secure