Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://securitytracker.com/id?1023409 | vdb entry third party advisory |
http://it.slashdot.org/story/10/01/05/1734242/ | third party advisory |
http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html | third party advisory |
http://www.verbatim.com/security/security-update.cfm | vendor advisory |
http://blogs.zdnet.com/hardware/?p=6655 | not applicable |
https://www.ironkey.com/usb-flash-drive-flaw-exposed | broken link |