{"api_version":"1","generated_at":"2026-07-23T07:18:06+00:00","cve":"CVE-2004-0838","urls":{"html":"https://cve.report/CVE-2004-0838","api":"https://cve.report/api/cve/CVE-2004-0838.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-0838","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-0838"},"summary":{"title":"CVE-2004-0838","description":"Lexar Safe Guard for JumpDrive Secure 1.0 stores the password insecurely in memory using XOR encryption, which allows local users to read the password directly from the device and access the password protected part of the drive.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-09-13 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/11162","name":"http://www.securityfocus.com/bid/11162","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Lexar JumpDrive Secure USB Flash Drive Insecure Password Storage Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.atstake.com/research/advisories/2004/a091304-1.txt","name":"http://www.atstake.com/research/advisories/2004/a091304-1.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17342","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17342","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/12522","name":"http://secunia.com/advisories/12522","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Lexar JumpDrive Secure Password Disclosure Security Issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-0838","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-0838","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"838","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"lexar","cpe5":"jumpdrive_secure","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:31:47.602Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"11162","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11162"},{"name":"12522","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/12522"},{"name":"A091304-1","tags":["vendor-advisory","x_refsource_ATSTAKE","x_transferred"],"url":"http://www.atstake.com/research/advisories/2004/a091304-1.txt"},{"name":"jumpdrive-safeguard-obtain-password(17342)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17342"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-09-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"Lexar Safe Guard for JumpDrive Secure 1.0 stores the password insecurely in memory using XOR encryption, which allows local users to read the password directly from the device and access the password protected part of the drive."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"11162","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11162"},{"name":"12522","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/12522"},{"name":"A091304-1","tags":["vendor-advisory","x_refsource_ATSTAKE"],"url":"http://www.atstake.com/research/advisories/2004/a091304-1.txt"},{"name":"jumpdrive-safeguard-obtain-password(17342)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17342"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-0838","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Lexar Safe Guard for JumpDrive Secure 1.0 stores the password insecurely in memory using XOR encryption, which allows local users to read the password directly from the device and access the password protected part of the drive."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"11162","refsource":"BID","url":"http://www.securityfocus.com/bid/11162"},{"name":"12522","refsource":"SECUNIA","url":"http://secunia.com/advisories/12522"},{"name":"A091304-1","refsource":"ATSTAKE","url":"http://www.atstake.com/research/advisories/2004/a091304-1.txt"},{"name":"jumpdrive-safeguard-obtain-password(17342)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17342"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-0838","datePublished":"2005-02-25T05:00:00.000Z","dateReserved":"2004-09-12T00:00:00.000Z","dateUpdated":"2024-08-08T00:31:47.602Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-09-13 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:lexar:jumpdrive_secure:*:*:*:*:*:*:*:*","matchCriteriaId":"93B9B72E-1CA2-4265-8ED9-A921495F5F3D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"838","Ordinal":"1","Title":"CVE-2004-0838","CVE":"CVE-2004-0838","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"838","Ordinal":"1","NoteData":"Lexar Safe Guard for JumpDrive Secure 1.0 stores the password insecurely in memory using XOR encryption, which allows local users to read the password directly from the device and access the password protected part of the drive.","Type":"Description","Title":"CVE-2004-0838"},{"CveYear":"2004","CveId":"838","Ordinal":"2","NoteData":"2005-02-25","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"838","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}