CVE-2007-2023
UnknownEPSS 0.34%
Last modified
CVE-2007-2023 is a vulnerability of currently unknown severity. USB20.dll in Secustick USB flash drive decouples the authorization and file access routines, which allows local users to bypass authentication requirements by altering the return value of the VerifyPassWord function.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
USB20.dll in Secustick USB flash drive decouples the authorization and file access routines, which allows local users to bypass authentication requirements by altering the return value of the VerifyPassWord function.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Secustick | Secustick Usb Flash Drive | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2023?
USB20.dll in Secustick USB flash drive decouples the authorization and file access routines, which allows local users to bypass authentication requirements by altering the return value of the VerifyPassWord function.
How severe is CVE-2007-2023?
Severity scoring for CVE-2007-2023 is pending analysis. The EPSS model estimates a 0.34% probability of exploitation in the next 30 days.
How do I fix CVE-2007-2023?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-2017siteadmin/useredit.php in AlstraSoft Video Share Enterprise …
- CVE-2007-2018SQL injection vulnerability in msg.php in AlstraSoft Video S…
- CVE-2007-2019PHP remote file inclusion vulnerability in init.gallery.php …
- CVE-2007-2020Unspecified vulnerability in administration.php in xodagalle…9.8
- CVE-2007-2021Multiple PHP remote file inclusion vulnerabilities in Pineap…
- CVE-2007-2022Adobe Macromedia Flash Player 7 and 9, when used with Opera …
- CVE-2007-2024Unrestricted file upload vulnerability in the UpLoad feature…
- CVE-2007-2025Unrestricted file upload vulnerability in the UpLoad feature…
- CVE-2007-2026The gnu regular expression code in file 4.20 allows context-…
- CVE-2007-2027Untrusted search path vulnerability in the add_filename_to_s…
- CVE-2007-2028Memory leak in freeRADIUS 1.1.5 and earlier allows remote at…
- CVE-2007-2029File descriptor leak in the PDF handler in Clam AntiVirus (C…
Are you affected by CVE-2007-2023?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
