CVE-2022-28382
Last modified
CVE-2022-28382 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in certain Verbatim drives through 2022-03-31. Due to the use of an insecure encryption AES mode (Electronic Codebook, aka ECB), an attacker may be able to extract information even from encrypted data, for example by observing repeating byte patterns. EPSS estimates a 1.63% chance of exploitation in the next 30 days.
Description
An issue was discovered in certain Verbatim drives through 2022-03-31. Due to the use of an insecure encryption AES mode (Electronic Codebook, aka ECB), an attacker may be able to extract information even from encrypted data, for example by observing repeating byte patterns. The firmware of the USB-to-SATA bridge controller INIC-3637EN uses AES-256 with the ECB mode. This operation mode of block ciphers (e.g., AES) always encrypts identical plaintext data, in this case blocks of 16 bytes, to identical ciphertext data. For some data, for instance bitmap images, the lack of the cryptographic property called diffusion, within ECB, can leak sensitive information even in encrypted data. Thus, the use of the ECB operation mode can put the confidentiality of specific information at risk, even in an encrypted form. This affects Keypad Secure USB 3.2 Gen 1 Drive Part Number #49428, Store 'n' Go Secure Portable HDD GD25LK01-3637-C VER4.0, Executive Fingerprint Secure SSD GDMSFE01-INI3637-C VER1.1, and Fingerprint Secure Portable Hard Drive Part Number #53650.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Verbatim | Keypad Secure Usb 3.2 Gen 1 Firmware | <= 2022-03-31 |
| Verbatim | Store \'N\' Go Secure Portable Hdd Firmware | <= 2022-03-31 |
| Verbatim | Executive Fingerprint Secure Ssd Firmware | <= 2022-03-31 |
| Verbatim | Fingerprint Secure Portable Hard Drive Firmware | <= 2022-03-31 |
References
- http://packetstormsecurity.com/files/167491/Verbatim-Keypad-Secure-USB-3.2-Gen-1-Drive-ECB-Issue.htmlExploit, Mailing List, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/167500/Verbatim-Store-N-Go-Secure-Portable-HDD-GD25LK01-3637-C-VER4.0-Risky-Crypto.htmlExploit, Mailing List, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/167528/Verbatim-Executive-Fingerprint-Secure-SSD-GDMSFE01-INI3637-C-VER1.1-Risky-Crypto.htmlExploit, Mailing List, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/167532/Verbatim-Fingerprint-Secure-Portable-Hard-Drive-53650-Risky-Crypto.htmlExploit, Mailing List, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/Jun/18Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Jun/22Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Jun/24Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Jun/9Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Oct/4Mailing List, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-002.txtExploit, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-006.txtExploit, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-010.txtExploit, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-015.txtExploit, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-044.txtExploit, Third Party Advisory
- http://packetstormsecurity.com/files/167491/Verbatim-Keypad-Secure-USB-3.2-Gen-1-Drive-ECB-Issue.htmlExploit, Mailing List, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/167500/Verbatim-Store-N-Go-Secure-Portable-HDD-GD25LK01-3637-C-VER4.0-Risky-Crypto.htmlExploit, Mailing List, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/167528/Verbatim-Executive-Fingerprint-Secure-SSD-GDMSFE01-INI3637-C-VER1.1-Risky-Crypto.htmlExploit, Mailing List, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/167532/Verbatim-Fingerprint-Secure-Portable-Hard-Drive-53650-Risky-Crypto.htmlExploit, Mailing List, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/Jun/18Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Jun/22Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Jun/24Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Jun/9Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Oct/4Mailing List, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-002.txtExploit, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-006.txtExploit, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-010.txtExploit, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-015.txtExploit, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-044.txtExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-28382?
How severe is CVE-2022-28382?
How do I fix CVE-2022-28382?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-28377On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and O…7.5
- CVE-2022-28378Craft CMS before 3.7.29 allows XSS.6.1
- CVE-2022-28379jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during…4.8
- CVE-2022-2838In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML …5.3
- CVE-2022-28380The rc-httpd component through 2022-03-31 for 9front (Plan 9…7.5
- CVE-2022-28381Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buff…9.8
- CVE-2022-28383An issue was discovered in certain Verbatim drives through 2…6.8
- CVE-2022-28384An issue was discovered in certain Verbatim drives through 2…5.5
- CVE-2022-28385An issue was discovered in certain Verbatim drives through 2…4.6
- CVE-2022-28386An issue was discovered in certain Verbatim drives through 2…4.6
- CVE-2022-28387An issue was discovered in certain Verbatim drives through 2…4.6
- CVE-2022-28388usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the…5.5
Are you affected by CVE-2022-28382?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
