CVE-2010-0221

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
07/01/2010
Last modified:
09/04/2025

Description

Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:kingston:datatraveler_blackbox:*:*:*:*:*:*:*:*
cpe:2.3:h:kingston:datatraveler_elite:*:*:privacy:*:*:*:*:*
cpe:2.3:h:kingston:datatraveler_secure:*:*:privacy:*:*:*:*:*