Verbatim's vulnerability footprint centers on encrypted storage and security-focused hardware devices, including fingerprint-secured SSDs, portable hard drives, and USB drives alongside their associated firmware. The recurring weakness classes—improper authentication attempt restriction, input validation gaps, cryptographic algorithm weaknesses, and insufficient data authenticity verification—reflect the authentication and encryption demands of self-encrypting storage devices. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Verbatim over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28382HIGH An issue was discovered in certain Verbatim drives through 2022-03-31. Due to the use of an insecure encryption AES mode (Electronic Codebook, aka ECB), an attacker may be able to | Jun 8, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-28383MEDIUM An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attacker can store malicious firmware code for the USB-to-SATA br | Jun 8, 2022 | 6.8 | 24 | NO | NO |
CVE-2022-28384MEDIUM An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they allow an offline brute-force attack for determining the correct passcode, and | Jun 8, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-28386MEDIUM An issue was discovered in certain Verbatim drives through 2022-03-31. The security feature for lockout (e.g., requiring a reformat of the drive after 20 failed unlock attempts) do | Jun 8, 2022 | 4.6 | 20 | NO | NO |
CVE-2022-28387MEDIUM An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they can be unlocked by an attacker who can then gain unauthorized access to the s | Jun 8, 2022 | 4.6 | 19 | NO | NO |
CVE-2022-28385MEDIUM An issue was discovered in certain Verbatim drives through 2022-03-31. Due to missing integrity checks, an attacker can manipulate the content of the emulated CD-ROM drive (contain | Jun 8, 2022 | 4.6 | 18 | NO | NO |
CVE-2010-0227MEDIUM Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which a | Jan 7, 2010 | 4.6 | 16 | NO | NO |
CVE-2010-0228MEDIUM Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for | Jan 7, 2010 | 4.6 | 15 | NO | NO |
CVE-2010-0229MEDIUM Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the clear | Jan 7, 2010 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Verbatim.
Media articles that mention a CVE ID that affects a product developed by Verbatim — matched by CVE ID, not by vendor name.