Lucene search

K
nvd[email protected]NVD:CVE-2022-28383
HistoryJun 08, 2022 - 4:15 p.m.

CVE-2022-28383

2022-06-0816:15:08
CWE-20
web.nvd.nist.gov
2
verbatim drives
firmware validation
usb-to-sata bridge
malicious code
physical access
supply chain
keypad secure usb
store 'n' go secure portable hdd
executive fingerprint secure ssd
fingerprint secure portable hard drive

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

50.7%

An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attacker can store malicious firmware code for the USB-to-SATA bridge controller on the USB drive (e.g., by leveraging physical access during the supply chain). This code is then executed. This affects Keypad Secure USB 3.2 Gen 1 Drive Part Number #49428, Store ‘n’ Go Secure Portable HDD GD25LK01-3637-C VER4.0, Executive Fingerprint Secure SSD GDMSFE01-INI3637-C VER1.1, and Fingerprint Secure Portable Hard Drive Part Number #53650.

Affected configurations

Nvd
Node
verbatimkeypad_secure_usb_3.2_gen_1_firmwareRange2022-03-31
AND
verbatimkeypad_secure_usb_3.2_gen_1Match-
Node
verbatimstore_\'n\'_go_secure_portable_hdd_firmwareRange2022-03-31
AND
verbatimstore_\'n\'_go_secure_portable_hddMatch-
Node
verbatimexecutive_fingerprint_secure_ssd_firmwareRange2022-03-31
AND
verbatimexecutive_fingerprint_secure_ssdMatch-
Node
verbatimfingerprint_secure_portable_hard_drive_firmwareRange2022-03-31
AND
verbatimfingerprint_secure_portable_hard_driveMatch-
VendorProductVersionCPE
verbatimkeypad_secure_usb_3.2_gen_1_firmware*cpe:2.3:o:verbatim:keypad_secure_usb_3.2_gen_1_firmware:*:*:*:*:*:*:*:*
verbatimkeypad_secure_usb_3.2_gen_1-cpe:2.3:h:verbatim:keypad_secure_usb_3.2_gen_1:-:*:*:*:*:*:*:*
verbatimstore_\'n\'_go_secure_portable_hdd_firmware*cpe:2.3:o:verbatim:store_\'n\'_go_secure_portable_hdd_firmware:*:*:*:*:*:*:*:*
verbatimstore_\'n\'_go_secure_portable_hdd-cpe:2.3:h:verbatim:store_\'n\'_go_secure_portable_hdd:-:*:*:*:*:*:*:*
verbatimexecutive_fingerprint_secure_ssd_firmware*cpe:2.3:o:verbatim:executive_fingerprint_secure_ssd_firmware:*:*:*:*:*:*:*:*
verbatimexecutive_fingerprint_secure_ssd-cpe:2.3:h:verbatim:executive_fingerprint_secure_ssd:-:*:*:*:*:*:*:*
verbatimfingerprint_secure_portable_hard_drive_firmware*cpe:2.3:o:verbatim:fingerprint_secure_portable_hard_drive_firmware:*:*:*:*:*:*:*:*
verbatimfingerprint_secure_portable_hard_drive-cpe:2.3:h:verbatim:fingerprint_secure_portable_hard_drive:-:*:*:*:*:*:*:*

References

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

50.7%

Related for NVD:CVE-2022-28383