Verbatim Corporate Secure Flash Drives Access Control Security Bypass Vulnerability
BID:37678
Info
Verbatim Corporate Secure Flash Drives Access Control Security Bypass Vulnerability
| Bugtraq ID: | 37678 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 08 2010 12:00AM |
| Updated: | Jan 08 2010 12:00AM |
| Credit: | Matthias Deeg and Sebastian Schreiber |
| Vulnerable: |
Verbatim Corporate Secure USB Flash Drive 0 Verbatim Corporate Secure FIPS Edition USB Flash Drive 0 |
| Not Vulnerable: | |
Discussion
Verbatim Corporate Secure Flash Drives Access Control Security Bypass Vulnerability
Verbatim Corporate Secure flash drives are prone to a local security-bypass vulnerability.
Attackers with physical access to an affected drive can exploit this issue to bypass password protection mechanisms to obtain data stored on the device.
The following devices are affected:
Verbatim Corporate Secure USB Flash Drive 1GB, 2GB, 4GB and 8GB
Verbatim Corporate Secure FIPS Edition USB Flash Drives 1GB, 2GB, 4GB and 8GB
Verbatim Corporate Secure flash drives are prone to a local security-bypass vulnerability.
Attackers with physical access to an affected drive can exploit this issue to bypass password protection mechanisms to obtain data stored on the device.
The following devices are affected:
Verbatim Corporate Secure USB Flash Drive 1GB, 2GB, 4GB and 8GB
Verbatim Corporate Secure FIPS Edition USB Flash Drives 1GB, 2GB, 4GB and 8GB
Exploit / POC
Verbatim Corporate Secure Flash Drives Access Control Security Bypass Vulnerability
To exploit this issue, an attacker would need physical access to the affected device.
To exploit this issue, an attacker would need physical access to the affected device.
Solution / Fix
Verbatim Corporate Secure Flash Drives Access Control Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Verbatim Corporate Secure Flash Drives Access Control Security Bypass Vulnerability
References:
References:
- Important Security Update December 2009 (Verbatim)
- Vendor Homepage (Verbatim)