PT-2022-18992 · Verbatim · Verbatim Drives

Matthias Deeg

·

Published

2022-06-08

·

Updated

2022-12-08

·

CVE-2022-28383

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Verbatim drives (affected versions not specified)
Description An issue was discovered in certain Verbatim drives due to insufficient firmware validation. An attacker can store malicious firmware code for the USB-to-SATA bridge controller on the USB drive, which is then executed. This affects various Verbatim drive models, including Keypad Secure USB 3.2 Gen 1 Drive, Store 'n' Go Secure Portable HDD, Executive Fingerprint Secure SSD, and Fingerprint Secure Portable Hard Drive.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-28383

Affected Products

Verbatim Drives