CVE-2004-1709 describes a vulnerability in the Datakey Rainbow iKey2032 USB token, specifically when utilizing the CIP client package. The core issue is a lack of encryption for communications between the token and its driver, potentially allowing local attackers to intercept and obtain user PINs. This vulnerability has a low severity CVSS score of 2.1, indicating a local attack vector with low complexity and a partial confidentiality impact. There is no evidence of active exploitation, nor is exploit code publicly available in common repositories like Metasploit or ExploitDB, and it has garnered no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:datakey:rainbow_ikey2032_usb_token:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.