CVE-2004-0838 describes an insecure password storage vulnerability in Lexar Safe Guard for JumpDrive Secure 1.0. The software stores passwords in memory using easily reversible XOR encryption, allowing local attackers to directly retrieve the password and access protected drive partitions. This vulnerability has a low CVSS score of 2.1, indicating a low attack complexity and impact, as it requires local access to the affected device. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has garnered some community discussion on GitHub.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:lexar:jumpdrive_secure:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.