CVE-2010-0225

SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sandisk:cruzer_enterprise_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:sandisk:cruzer_enterprise:-:*:*:*:*:*:*:*

History

07 Nov 2023, 02:05

Type Values Removed Values Added
References
  • {'url': 'http://www.syss.de/index.php?id=108&tx_ttnews[tt_news]=528&cHash=8d16fa63d9', 'name': 'http://www.syss.de/index.php?id=108&tx_ttnews[tt_news]=528&cHash=8d16fa63d9', 'tags': ['Broken Link'], 'refsource': 'MISC'}
  • () http://www.syss.de/index.php?id=108&tx_ttnews%5Btt_news%5D=528&cHash=8d16fa63d9 -

10 Feb 2022, 17:04

Type Values Removed Values Added
CWE CWE-310 CWE-312
CPE cpe:2.3:h:scandisk:cruzer_enterprise_usb:*:*:*:*:*:*:*:* cpe:2.3:o:sandisk:cruzer_enterprise_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:sandisk:cruzer_enterprise:-:*:*:*:*:*:*:*
First Time Sandisk cruzer Enterprise
Sandisk cruzer Enterprise Firmware
Sandisk
References (MISC) https://www.ironkey.com/usb-flash-drive-flaw-exposed - (MISC) https://www.ironkey.com/usb-flash-drive-flaw-exposed - Broken Link
References (MISC) http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_SanDisk_USB-Stick.pdf - (MISC) http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_SanDisk_USB-Stick.pdf - Broken Link
References (MISC) http://www.syss.de/index.php?id=108&tx_ttnews[tt_news]=528&cHash=8d16fa63d9 - (MISC) http://www.syss.de/index.php?id=108&tx_ttnews[tt_news]=528&cHash=8d16fa63d9 - Broken Link
References (MISC) http://blogs.zdnet.com/hardware/?p=6655 - (MISC) http://blogs.zdnet.com/hardware/?p=6655 - Broken Link
References (MISC) http://it.slashdot.org/story/10/01/05/1734242/ - (MISC) http://it.slashdot.org/story/10/01/05/1734242/ - Third Party Advisory
References (MISC) http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html - (MISC) http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html - Third Party Advisory
References (VUPEN) http://www.vupen.com/english/advisories/2010/0078 - (VUPEN) http://www.vupen.com/english/advisories/2010/0078 - Third Party Advisory
References (BID) http://www.securityfocus.com/bid/37677 - (BID) http://www.securityfocus.com/bid/37677 - Third Party Advisory, VDB Entry

Information

Published : 2010-01-07 19:30

Updated : 2023-12-10 11:03


NVD link : CVE-2010-0225

Mitre link : CVE-2010-0225

CVE.ORG link : CVE-2010-0225


JSON object : View

Products Affected

sandisk

  • cruzer_enterprise
  • cruzer_enterprise_firmware
CWE
CWE-312

Cleartext Storage of Sensitive Information