Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program.
References
Link | Resource |
---|---|
http://blogs.zdnet.com/hardware/?p=6655 | Not Applicable |
http://it.slashdot.org/story/10/01/05/1734242/ | Third Party Advisory |
http://securitytracker.com/id?1023409 | Third Party Advisory VDB Entry |
http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html | Third Party Advisory |
http://www.verbatim.com/security/security-update.cfm | Vendor Advisory |
https://www.ironkey.com/usb-flash-drive-flaw-exposed | Broken Link |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2010-01-07 19:30
Updated : 2024-02-04 17:54
NVD link : CVE-2010-0227
Mitre link : CVE-2010-0227
CVE.ORG link : CVE-2010-0227
JSON object : View
Products Affected
verbatim
- corporate_secure
CWE
CWE-255
Credentials Management Errors