Vulnerabilities > CVE-2022-28387 - Unspecified vulnerability in Verbatim products
Attack vector
PHYSICAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE low complexity
verbatim
Summary
An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they can be unlocked by an attacker who can then gain unauthorized access to the stored data. The attacker can simply use an undocumented IOCTL command that retrieves the correct password. This affects Executive Fingerprint Secure SSD GDMSFE01-INI3637-C VER1.1 and Fingerprint Secure Portable Hard Drive Part Number #53650.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 2 | |
Hardware | 2 |
References
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-009.txt
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-014.txt
- http://seclists.org/fulldisclosure/2022/Jun/13
- http://seclists.org/fulldisclosure/2022/Jun/21
- http://packetstormsecurity.com/files/167531/Verbatim-Fingerprint-Secure-Portable-Hard-Drive-53650-Risky-Crypto.html
- http://packetstormsecurity.com/files/167527/Verbatim-Executive-Fingerprint-Secure-SSD-GDMSFE01-INI3637-C-VER1.1-Risky-Crypto.html