Vulnerability Description
eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB traffic or by sending a 06 05 52 41 01 b0 00 00 00 00 00 00 SCSI command.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eye-Disk | Eyedisk | - |
Related Weaknesses (CWE)
References
- https://www.pentestpartners.com/security-blog/eyedisk-hacking-the-unhackable-agaExploitThird Party Advisory
- https://www.pentestpartners.com/security-blog/eyedisk-hacking-the-unhackable-agaExploitThird Party Advisory
FAQ
What is CVE-2019-11885?
CVE-2019-11885 is a vulnerability with a CVSS score of 6.8 (MEDIUM). eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB traffic or by sending a 06 05 52 41 01 b0 00 00 00 00 00 00 SCSI command.
How severe is CVE-2019-11885?
CVE-2019-11885 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-11885?
Check the references section above for vendor advisories and patch information. Affected products include: Eye-Disk Eyedisk.