SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
http://www.syss.de/index.php?id=108&tx_ttnews%5Btt_news%5D=528&cHash=8d16fa63d9 | |
http://www.sandisk.com/business-solutions/enterprise/technical-support/security-bulletin-december-2009 | vendor advisory |
http://it.slashdot.org/story/10/01/05/1734242/ | third party advisory |
http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html | third party advisory |
http://blogs.zdnet.com/hardware/?p=6655 | broken link |
http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_SanDisk_USB-Stick.pdf | broken link |
http://www.vupen.com/english/advisories/2010/0078 | vdb entry third party advisory |
http://www.securityfocus.com/bid/37677 | vdb entry third party advisory |
https://www.ironkey.com/usb-flash-drive-flaw-exposed | broken link |