CVE Feed

    Dashboard / CVE / CVE-2022-28382

    CVE-2022-28382

    An issue was discovered in certain Verbatim drives through 2022-03-31. Due to the use of an insecure encryption AES mode (Electronic Codebook, aka ECB), an attacker may be able to extract information even from encrypted data, for example by observing repeating byte patterns. The firmware of the USB-to-SATA bridge controller INIC-3637EN uses AES-256 with the ECB mode. This operation mode of block ciphers (e.g., AES) always encrypts identical plaintext data, in this case blocks of 16 bytes, to identical ciphertext data. For some data, for instance bitmap images, the lack of the cryptographic property called diffusion, within ECB, can leak sensitive information even in encrypted data. Thus, the use of the ECB operation mode can put the confidentiality of specific information at risk, even in an encrypted form. This affects Keypad Secure USB 3.2 Gen 1 Drive Part Number #49428, Store 'n' Go Secure Portable HDD GD25LK01-3637-C VER4.0, Executive Fingerprint Secure SSD GDMSFE01-INI3637-C VER1.1, and Fingerprint Secure Portable Hard Drive Part Number #53650.

    Published:Jun 8, 2022
    Last Modified:Nov 21, 2024
    EPS:Jun 8, 2022
    EPSS Score:0.00403
    CVSS Score:7.5

    Affected Products

    Vendor
    Verbatim
    Product
    Executive Fingerprint Secure Ssd
    Vendor
    Verbatim
    Product
    Executive Fingerprint Secure Ssd Firmware
    Vendor
    Verbatim
    Product
    Fingerprint Secure Portable Hard Drive
    Vendor
    Verbatim
    Product
    Fingerprint Secure Portable Hard Drive Firmware
    Vendor
    Verbatim
    Product
    Keypad Secure Usb 3.2 Gen 1
    Vendor
    Verbatim
    Product
    Keypad Secure Usb 3.2 Gen 1 Firmware
    Vendor
    Verbatim
    Product
    Store \'n\' Go Secure Portable Hdd
    Vendor
    Verbatim
    Product
    Store \'n\' Go Secure Portable Hdd Firmware

    Exploits

    http://packetstormsecurity.com/files/167491/Verbatim-Keypad-Secure-USB-3.2-Gen-1-Drive-ECB-Issue.htmlhttp://packetstormsecurity.com/files/167500/Verbatim-Store-N-Go-Secure-Portable-HDD-GD25LK01-3637-C-VER4.0-Risky-Crypto.htmlhttp://packetstormsecurity.com/files/167528/Verbatim-Executive-Fingerprint-Secure-SSD-GDMSFE01-INI3637-C-VER1.1-Risky-Crypto.htmlhttp://packetstormsecurity.com/files/167532/Verbatim-Fingerprint-Secure-Portable-Hard-Drive-53650-Risky-Crypto.htmlhttp://seclists.org/fulldisclosure/2022/Jun/18http://seclists.org/fulldisclosure/2022/Jun/22http://seclists.org/fulldisclosure/2022/Jun/24http://seclists.org/fulldisclosure/2022/Jun/9https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-002.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-006.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-010.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-015.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-044.txthttp://packetstormsecurity.com/files/167491/Verbatim-Keypad-Secure-USB-3.2-Gen-1-Drive-ECB-Issue.htmlhttp://packetstormsecurity.com/files/167500/Verbatim-Store-N-Go-Secure-Portable-HDD-GD25LK01-3637-C-VER4.0-Risky-Crypto.htmlhttp://packetstormsecurity.com/files/167528/Verbatim-Executive-Fingerprint-Secure-SSD-GDMSFE01-INI3637-C-VER1.1-Risky-Crypto.htmlhttp://packetstormsecurity.com/files/167532/Verbatim-Fingerprint-Secure-Portable-Hard-Drive-53650-Risky-Crypto.htmlhttp://seclists.org/fulldisclosure/2022/Jun/18http://seclists.org/fulldisclosure/2022/Jun/22http://seclists.org/fulldisclosure/2022/Jun/24http://seclists.org/fulldisclosure/2022/Jun/9https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-002.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-006.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-010.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-015.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-044.txt

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High