VulnerabilityModified
CVE-2010-0225
SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.
MEDIUM 4.6EPSS 0.28%
Does this matter?
Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.
Description
SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.28% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-312
- Affected
- sandisk/cruzer enterprise firmware
- Source
- cve@mitre.org
References
- http://blogs.zdnet.com/hardware/?p=6655Broken Link
- http://it.slashdot.org/story/10/01/05/1734242/Third Party Advisory
- http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.htmlThird Party Advisory
- http://www.sandisk.com/business-solutions/enterprise/technical-support/security-bulletin-december-2009Vendor Advisory
- http://www.securityfocus.com/bid/37677Third Party Advisory, VDB Entry
- http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_SanDisk_USB-Stick.pdfBroken Link
- http://www.syss.de/index.php?id=108&tx_ttnews%5Btt_news%5D=528&cHash=8d16fa63d9
- http://www.vupen.com/english/advisories/2010/0078Third Party Advisory
- https://www.ironkey.com/usb-flash-drive-flaw-exposedBroken Link
- http://blogs.zdnet.com/hardware/?p=6655Broken Link
- http://it.slashdot.org/story/10/01/05/1734242/Third Party Advisory
- http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.htmlThird Party Advisory
- http://www.sandisk.com/business-solutions/enterprise/technical-support/security-bulletin-december-2009Vendor Advisory
- http://www.securityfocus.com/bid/37677Third Party Advisory, VDB Entry
- http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_SanDisk_USB-Stick.pdfBroken Link
- http://www.syss.de/index.php?id=108&tx_ttnews%5Btt_news%5D=528&cHash=8d16fa63d9
- http://www.vupen.com/english/advisories/2010/0078Third Party Advisory
- https://www.ironkey.com/usb-flash-drive-flaw-exposedBroken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.