MEDIUM
SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key
Published Jan 7, 2010
4.6
MEDIUMCVSS 2.0
EPSS 0.28%
Description
SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.
Affected products
No data.
AND
- n/a
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://blogs.zdnet.com/hardware/?p=6655 x_refsource_MISCBroken Link
- http://it.slashdot.org/story/10/01/05/1734242/ x_refsource_MISCThird Party Advisory
- http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html x_refsource_MISCThird Party Advisory
- http://www.sandisk.com/business-solutions/enterprise/technical-support/security-bulletin-december-2009 x_refsource_MISCVendor Advisory
- http://www.securityfocus.com/bid/37677 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_SanDisk_USB-Stick.pdf x_refsource_MISCBroken Link
- http://www.syss.de/index.php?id=108&tx_ttnews%5Btt_news%5D=528&cHash=8d16fa63d9 x_refsource_MISC
- http://www.vupen.com/english/advisories/2010/0078 vdb-entryx_refsource_VUPENThird Party Advisory
- https://www.ironkey.com/usb-flash-drive-flaw-exposed x_refsource_MISCBroken Link
| Link | Providers | Tags |
|---|---|---|
| http://blogs.zdnet.com/hardware/?p=6655 | x_refsource_MISCBroken Link | |
| http://it.slashdot.org/story/10/01/05/1734242/ | x_refsource_MISCThird Party Advisory | |
| http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html | x_refsource_MISCThird Party Advisory | |
| http://www.sandisk.com/business-solutions/enterprise/technical-support/security-bulletin-december-2009 | x_refsource_MISCVendor Advisory | |
| http://www.securityfocus.com/bid/37677 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_SanDisk_USB-Stick.pdf | x_refsource_MISCBroken Link | |
| http://www.syss.de/index.php?id=108&tx_ttnews%5Btt_news%5D=528&cHash=8d16fa63d9 | x_refsource_MISC | |
| http://www.vupen.com/english/advisories/2010/0078 | vdb-entryx_refsource_VUPENThird Party Advisory | |
| https://www.ironkey.com/usb-flash-drive-flaw-exposed | x_refsource_MISCBroken Link |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 7, 2010
Updated Aug 7, 2024
Reserved Jan 7, 2010
Link CVE-2010-0225
CISA Vulnrichment
Updated n/a