VulnerabilityModified
CVE-2017-16242
The fingerprint authentication requirement for data access can be bypassed.
MEDIUM 6.8EPSS 0.50%
Does this matter?
Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authentication requirement for data access can be bypassed. An attacker with physical access can send a static packet to a serial port exposed on the PCB to unlock the key and get access to the data without possessing the required fingerprint.
- CVSS 3.0
- 6.8 MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.50% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- meco/usb memory stick with fingerprint firwmare
- Source
- cve@mitre.org
References
- https://gist.github.com/audebert/ef6e206a27ededd1386cff48604e9335Third Party Advisory
- https://www.blackhat.com/docs/us-17/thursday/us-17-Picod-Attacking-Encrypted-USB-Keys-The-Hard%28ware%29-Way.pdf
- https://www.blackhat.com/us-17/briefings/schedule/index.html#attacking-encrypted-usb-keys-the-hardware-way-7443Third Party Advisory
- https://www.elie.net/talk/attacking-encrypted-usb-keys-the-hardware-wayThird Party Advisory
- https://gist.github.com/audebert/ef6e206a27ededd1386cff48604e9335Third Party Advisory
- https://www.blackhat.com/docs/us-17/thursday/us-17-Picod-Attacking-Encrypted-USB-Keys-The-Hard%28ware%29-Way.pdf
- https://www.blackhat.com/us-17/briefings/schedule/index.html#attacking-encrypted-usb-keys-the-hardware-way-7443Third Party Advisory
- https://www.elie.net/talk/attacking-encrypted-usb-keys-the-hardware-wayThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.