CVE-2022-28385 describes a missing integrity check vulnerability in Verbatim Executive Fingerprint Secure SSD and Fingerprint Secure Portable Hard Drive products. An attacker can manipulate the content of the emulated CD-ROM drive, which stores client software, by modifying a hidden ISO-9660 image. This allows for the storage and potential execution of malicious software when the device is used. The vulnerability has a CVSS score of 4.6 (Medium), indicating a physical attack vector with low complexity and high confidentiality impact, but no integrity or availability impact. An attacker with temporary physical access could program a modified ISO-9660 image, potentially leading to the decryption of user data if they later gain access to the USB drive. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. However, there has been some community discussion, including a Reddit post detailing the hacking of a Verbatim Secure USB Flash Drive.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2022-03-31CPE matchmatch criteria | cpe:2.3:o:verbatim:executive_fingerprint_secure_ssd_firmware:*:*:*:*:*:*:*:* | ||
<= 2022-03-31CPE matchmatch criteria | cpe:2.3:o:verbatim:fingerprint_secure_portable_hard_drive_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.