CVE-2021-28653

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/03/2021
Last modified:
27/08/2021

Description

The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They choose a non-preferred storage mechanism if the device has Secure Enclave support but lacks biometric authentication hardware.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:westerndigital:armorlock:*:*:*:*:*:iphone_os:*:* 1.4.1 (excluding)
cpe:2.3:a:westerndigital:armorlock:*:*:*:*:*:macos:*:* 1.4.1 (excluding)