Sandisk's vulnerability profile centers on a narrow portfolio of data-storage and security appliances, including USB drives, SSD management tools, and encryption software that protect sensitive data on endpoint devices. The recurring weakness classes—cleartext and insecure storage of credentials, hard-coded secrets, and insufficient authentication controls—reflect the authentication and encryption-boundary demands of products designed to safeguard sensitive information at rest and in transit. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sandisk over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36750HIGH ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under m | Dec 22, 2021 | 8.1 | 33 | NO | NO |
CVE-2019-13466HIGH Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The “generate reports” archive is protected with a hard-coded p | Sep 30, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-13467MEDIUM Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the app | Sep 30, 2019 | 5.9 | 22 | NO | NO |
CVE-2010-0226MEDIUM SanDisk Cruzer Enterprise USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a | Jan 7, 2010 | 4.6 | 18 | NO | NO |
CVE-2010-0225MEDIUM SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to | Jan 7, 2010 | 4.6 | 17 | NO | NO |
CVE-2010-0224MEDIUM SanDisk Cruzer Enterprise USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attacke | Jan 7, 2010 | 4.6 | 17 | NO | NO |
CVE-2017-16560MEDIUM SanDisk Secure Access 3.01 vault decrypts and copies encrypted files to a temporary folder, where they can remain indefinitely in certain situations, such as if the file is being e | Nov 16, 2017 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sandisk.
Media articles that mention a CVE ID that affects a product developed by Sandisk — matched by CVE ID, not by vendor name.