CVE Feed

    Dashboard / CVE / CVE-2022-28383

    CVE-2022-28383

    An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attacker can store malicious firmware code for the USB-to-SATA bridge controller on the USB drive (e.g., by leveraging physical access during the supply chain). This code is then executed. This affects Keypad Secure USB 3.2 Gen 1 Drive Part Number #49428, Store 'n' Go Secure Portable HDD GD25LK01-3637-C VER4.0, Executive Fingerprint Secure SSD GDMSFE01-INI3637-C VER1.1, and Fingerprint Secure Portable Hard Drive Part Number #53650.

    Published:Jun 8, 2022
    Last Modified:Nov 21, 2024
    EPS:Jun 8, 2022
    EPSS Score:0.00075
    CVSS Score:6.8

    Affected Products

    Vendor
    Verbatim
    Product
    Executive Fingerprint Secure Ssd
    Vendor
    Verbatim
    Product
    Executive Fingerprint Secure Ssd Firmware
    Vendor
    Verbatim
    Product
    Fingerprint Secure Portable Hard Drive
    Vendor
    Verbatim
    Product
    Fingerprint Secure Portable Hard Drive Firmware
    Vendor
    Verbatim
    Product
    Keypad Secure Usb 3.2 Gen 1
    Vendor
    Verbatim
    Product
    Keypad Secure Usb 3.2 Gen 1 Firmware
    Vendor
    Verbatim
    Product
    Store \'n\' Go Secure Portable Hdd
    Vendor
    Verbatim
    Product
    Store \'n\' Go Secure Portable Hdd Firmware

    Exploits

    http://packetstormsecurity.com/files/167482/Verbatim-Keypad-Secure-USB-3.2-Gen-1-Drive-Missing-Control.htmlhttp://packetstormsecurity.com/files/167508/Verbatim-Store-N-Go-Secure-Portable-HDD-GD25LK01-3637-C-VER4.0-Missing-Trust.htmlhttp://packetstormsecurity.com/files/167535/Verbatim-Fingerprint-Secure-Portable-Hard-Drive-53650-Missing-Trust.htmlhttp://packetstormsecurity.com/files/167539/Verbatim-Executive-Fingerprint-Secure-SSD-GDMSFE01-INI3637-C-VER1.1-Missing-Trust.htmlhttp://seclists.org/fulldisclosure/2022/Jun/10http://seclists.org/fulldisclosure/2022/Jun/12http://seclists.org/fulldisclosure/2022/Jun/19http://seclists.org/fulldisclosure/2022/Jun/25https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-003.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-007.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-011.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-016.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-045.txthttp://packetstormsecurity.com/files/167482/Verbatim-Keypad-Secure-USB-3.2-Gen-1-Drive-Missing-Control.htmlhttp://packetstormsecurity.com/files/167508/Verbatim-Store-N-Go-Secure-Portable-HDD-GD25LK01-3637-C-VER4.0-Missing-Trust.htmlhttp://packetstormsecurity.com/files/167535/Verbatim-Fingerprint-Secure-Portable-Hard-Drive-53650-Missing-Trust.htmlhttp://packetstormsecurity.com/files/167539/Verbatim-Executive-Fingerprint-Secure-SSD-GDMSFE01-INI3637-C-VER1.1-Missing-Trust.htmlhttp://seclists.org/fulldisclosure/2022/Jun/10http://seclists.org/fulldisclosure/2022/Jun/12http://seclists.org/fulldisclosure/2022/Jun/19http://seclists.org/fulldisclosure/2022/Jun/25https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-003.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-007.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-011.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-016.txthttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-045.txt

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High