CVE-2010-0223

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
07/01/2010
Last modified:
09/04/2025

Description

Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a key that was captured in a USB data stream at an earlier time.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:kingston:datatraveler_blackbox:*:*:*:*:*:*:*:*
cpe:2.3:h:kingston:datatraveler_elite:*:*:privacy:*:*:*:*:*
cpe:2.3:h:kingston:datatraveler_secure:*:*:privacy:*:*:*:*:*