CERT-In Vulnerability Note
CIVN-2021-0381
Vulnerability in SanDisk SecureAccess
Original Issue Date:December 31, 2021
Severity Rating: HIGH
Software Affected
- SanDisk Secure Access 3.02
Overview
A vulnerability has been reported in SanDisk Secure Access which could allow an attacker to gain unauthorized access of data on the targeted system.
Description
This vulnerability exists in SanDisk Secure Access due to improper handling of a one-way cryptographic hash with a predictable salt. An attacker could exploit this vulnerability by executed brute force attack on user passwords.
Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access of data on the targeted system.
Solution
Apply appropriate update to the latest version:
https://kb.sandisk.com/app/answers/detail/a_id/23775
Vendor Information
Western Digital
https://www.westerndigital.com/support/product-security/wdc-21014-sandisk-secureaccess-software-update
References
Western Digital
https://www.westerndigital.com/support/product-security/wdc-21014-sandisk-secureaccess-software-update
CVE Name
CVE-2021-36750
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|