Записи SanDisk
8 опубликованных записей вендора sandisk.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-255 Credentials Management Errors2
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-798 Use of Hard-coded Credentials1
- CWE-922 Insecure Storage of Sensitive Information1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2021-36750Proof of concept | ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVauzendesk · enc datavault · CWE-307 | Высокая8,1 | — | 13,5 % | 22 дек. 2021 г. |
30Наблюдать | CVE-2019-13466Эксплойта нет | Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control.sandisk · ssd dashboard · CWE-798 | Высокая7,5 | — | 0,7 % | 30 сент. 2019 г. |
23Наблюдать | CVE-2019-13467Эксплойта нет | Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable tsandisk · ssd dashboard | Средняя5,9 | — | 1,5 % | 30 сент. 2019 г. |
23Наблюдать | CVE-2024-22168Эксплойта нет | Cross-Site Scripting (XSS) vulnerability on Western Digital My Cloud and SanDisk ibi Web Appswestern digital · my cloud home web app · CWE-79 | Средняя5,9 | — | 0,3 % | 24 июн. 2024 г. |
18Наблюдать | CVE-2010-0224Эксплойта нет | SanDisk Cruzer Enterprise USB flash drives validate passwords with a program running on the host computer rather than the device hardware, wsandisk · cruzer enterprise usb · CWE-255 | Средняя4,6 | — | 0,4 % | 7 янв. 2010 г. |
18Наблюдать | CVE-2010-0226Эксплойта нет | SanDisk Cruzer Enterprise USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access thesandisk · cruzer enterprise usb · CWE-255 | Средняя4,6 | — | 0,3 % | 7 янв. 2010 г. |
18Наблюдать | CVE-2010-0225Эксплойта нет | SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easisandisk · cruzer enterprise firmware · CWE-312 | Средняя4,6 | — | 0,3 % | 7 янв. 2010 г. |
17Наблюдать | CVE-2017-16560Эксплойта нет | SanDisk Secure Access 3.01 vault decrypts and copies encrypted files to a temporary folder, where they can remain indefinitely in certain sisandisk · secureaccess · CWE-922 | Средняя4,3 | — | 0,4 % | 16 нояб. 2017 г. |
- CVE-2021-3675036Наблюдать
ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVau
ВысокаяCVSS 8,1Proof of conceptEPSS 14 %zendesk · enc datavault22 дек. 2021 г.
- CVE-2019-1346630Наблюдать
Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %sandisk · ssd dashboard30 сент. 2019 г.
- CVE-2019-1346723Наблюдать
Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable t
СредняяCVSS 5,9Эксплойта нетEPSS 2 %sandisk · ssd dashboard30 сент. 2019 г.
- CVE-2024-2216823Наблюдать
Cross-Site Scripting (XSS) vulnerability on Western Digital My Cloud and SanDisk ibi Web Apps
СредняяCVSS 5,9Эксплойта нетEPSS 0 %western digital · my cloud home web app24 июн. 2024 г.
- CVE-2010-022418Наблюдать
SanDisk Cruzer Enterprise USB flash drives validate passwords with a program running on the host computer rather than the device hardware, w
СредняяCVSS 4,6Эксплойта нетEPSS 0 %sandisk · cruzer enterprise usb7 янв. 2010 г.
- CVE-2010-022618Наблюдать
SanDisk Cruzer Enterprise USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the
СредняяCVSS 4,6Эксплойта нетEPSS 0 %sandisk · cruzer enterprise usb7 янв. 2010 г.
- CVE-2010-022518Наблюдать
SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easi
СредняяCVSS 4,6Эксплойта нетEPSS 0 %sandisk · cruzer enterprise firmware7 янв. 2010 г.
- CVE-2017-1656017Наблюдать
SanDisk Secure Access 3.01 vault decrypts and copies encrypted files to a temporary folder, where they can remain indefinitely in certain si
СредняяCVSS 4,3Эксплойта нетEPSS 0 %sandisk · secureaccess16 нояб. 2017 г.