Dallas Semiconductor iButton DS1991 returns predictable values when given an incorrect password, which makes it easier for users with physical access to conduct dictionary attacks against the device password.
Link | Tags |
---|---|
http://www.atstake.com/research/advisories/2001/a011801-1.txt | vendor advisory exploit |
http://www.kb.cert.org/vuls/id/178560 | us government resource exploit third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/10625 | vdb entry |