MEDIUM · 4.6

CVE-2010-0224

SanDisk Cruzer Enterprise USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cle...

Vulnerability Description

SanDisk Cruzer Enterprise USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
SandiskCruzer Enterprise UsbAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-0224?

CVE-2010-0224 is a vulnerability with a CVSS score of 4.6 (MEDIUM). SanDisk Cruzer Enterprise USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cle...

How severe is CVE-2010-0224?

CVE-2010-0224 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-0224?

Check the references section above for vendor advisories and patch information. Affected products include: Sandisk Cruzer Enterprise Usb.