{"id":25979,"date":"2022-06-20T21:20:03","date_gmt":"2022-06-20T17:20:03","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/167546\/SYSS-2022-013.txt"},"modified":"2022-06-26T08:49:51","modified_gmt":"2022-06-26T04:19:51","slug":"verbatim-executive-fingerprint-secure-ssd-gdmsfe01-ini3637-c-ver1-1-insufficient-verification","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/verbatim-executive-fingerprint-secure-ssd-gdmsfe01-ini3637-c-ver1-1-insufficient-verification\/","title":{"rendered":"Verbatim Executive Fingerprint Secure SSD GDMSFE01-INI3637-C VER1.1 Insufficient Verification"},"content":{"rendered":"<p dir=\"ltr\">Advisory ID: SYSS-2022-013<br \/>\nProduct: Executive Fingerprint Secure SSD<br \/>\nManufacturer: Verbatim<br \/>\nAffected Version(s): GDMSFE01-INI3637-C VER1.1<br \/>\nTested Version(s): GDMSFE01-INI3637-C VER1.1<br \/>\nVulnerability Type: Insufficient Verification of Data<br \/>\nAuthenticity (CWE-345)<br \/>\nRisk Level: Low<br \/>\nSolution Status: Open<br \/>\nManufacturer Notification: 2022-02-03<br \/>\nSolution Date: &#8211;<br \/>\nPublic Disclosure: 2022-06-08<br \/>\nCVE Reference: CVE-2022-28385<br \/>\nAuthor of Advisory: Matthias Deeg (SySS GmbH)<\/p>\n<p dir=\"ltr\">~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p dir=\"ltr\">Overview:<\/p>\n<p dir=\"ltr\">The Verbatim Executive Fingerprint Secure SSD is a USB drive with AES<br \/>\n256-bit hardware encryption and a built-in fingerprint sensor for<br \/>\nunlocking the device with previously registered fingerprints.<\/p>\n<p dir=\"ltr\">The manufacturer describes the product as follows:<\/p>\n<p dir=\"ltr\">&#8220;The AES 256-bit Hardware Encryption seamlessly encrypts all data on the<br \/>\ndrive in real-time. The drive is compliant with GDPR requirements as<br \/>\n100% of the drive is securely encrypted. The built-in fingerprint<br \/>\nrecognition system allows access for up to eight authorised users and<br \/>\none administrator who can access the device via a password. The SSD<br \/>\ndoes not store passwords in the computer or system&#8217;s volatile memory<br \/>\nmaking it far more secure than software encryption.&#8221;[1]\n<p dir=\"ltr\">Due to missing integrity checks, an attacker can manipulate the content<br \/>\nof the emulated CD-ROM drive containing the Windows and macOS client<br \/>\nsoftware.<\/p>\n<p dir=\"ltr\">~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p dir=\"ltr\">Vulnerability Details:<\/p>\n<p dir=\"ltr\">When analyzing the Verbatim Executive Fingerprint Secure SSD, Matthias<br \/>\nDeeg found out that the content of the emulated CD-ROM drive containing<br \/>\nthe Windows and macOS client software can be manipulated.<\/p>\n<p dir=\"ltr\">The content of this emulated CD-ROM drive is stored as ISO-9660 image<br \/>\nin the &#8220;hidden&#8221; sectors of the USB drive that can only be accessed<br \/>\nusing special IOCTL commands, or when installing the drive in an<br \/>\nexternal disk enclosure.<\/p>\n<p dir=\"ltr\">The following output exemplarily shows the content of the ISO-9660<br \/>\nfile system:<\/p>\n<p dir=\"ltr\"># mount hidden_sectors.bin \/mnt\/<\/p>\n<p dir=\"ltr\"># lsd -laR \/mnt\/<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 .<br \/>\ndrwxr-xr-x root root 4.0 KB Fri Jan 7 16:39:47 2022 \uf115 ..<br \/>\n.r-xr-xr-x root root 70 B Wed Aug 14 09:20:40 2019 \uf016 Autorun.inf<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 MAC<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 Windows<\/p>\n<p dir=\"ltr\">\/mnt\/MAC:<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 .<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 ..<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 setup.app<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 Source<\/p>\n<p dir=\"ltr\">\/mnt\/MAC\/setup.app:<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 .<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 ..<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 Contents<\/p>\n<p dir=\"ltr\">\/mnt\/MAC\/setup.app\/Contents:<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 .<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 ..<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 _CodeSignature<br \/>\n.r-xr-xr-x root root 1.4 KB Thu Oct 24 06:58:18 2019 \uf016 Info.plist<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 MacOS<br \/>\n.r-xr-xr-x root root 8 B Thu Oct 24 06:58:18 2019 \uf016 PkgInfo<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 Resources<\/p>\n<p dir=\"ltr\">\/mnt\/MAC\/setup.app\/Contents\/_CodeSignature:<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 .<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 ..<br \/>\n.r-xr-xr-x root root 3.6 KB Thu Oct 24 07:06:02 2019 \uf016 CodeResources<\/p>\n<p dir=\"ltr\">\/mnt\/MAC\/setup.app\/Contents\/MacOS:<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 .<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 ..<br \/>\n.r-xr-xr-x root root 30 KB Thu Oct 24 07:06:02 2019 \uf016 setup<\/p>\n<p dir=\"ltr\">\/mnt\/MAC\/setup.app\/Contents\/Resources:<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 .<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 ..<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 Base.lproj<\/p>\n<p dir=\"ltr\">\/mnt\/MAC\/setup.app\/Contents\/Resources\/Base.lproj:<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 .<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 ..<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 Main.storyboardc<\/p>\n<p dir=\"ltr\">\/mnt\/MAC\/setup.app\/Contents\/Resources\/Base.lproj\/Main.storyboardc:<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 .<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 ..<br \/>\n.r-xr-xr-x root root 445 B Thu Oct 24 06:58:18 2019 \uf016 Info.plist<br \/>\n.r-xr-xr-x root root 35 KB Thu Oct 24 06:58:18 2019 \uf016 MainMenu.nib<br \/>\n.r-xr-xr-x root root 3.5 KB Thu Oct 24 06:58:18 2019 \uf016<br \/>\nNSWindowController-B8D-0N-5wS.nib<br \/>\n.r-xr-xr-x root root 1.2 KB Thu Oct 24 06:58:18 2019 \uf016<br \/>\nXfG-lQ-9wD-view-m2S-Jp-Qdl.nib<\/p>\n<p dir=\"ltr\">\/mnt\/MAC\/Source:<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 .<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 ..<br \/>\n.r-xr-xr-x root root 5.9 MB Mon Jul 22 06:22:24 2019 \uf410 gtk_dylib.tar<br \/>\n.r-xr-xr-x root root 1.0 MB Thu Oct 24 07:23:30 2019 \uf410<br \/>\nVERBATIM_FPTOOL_B0_V1.2.tar<\/p>\n<p dir=\"ltr\">\/mnt\/Windows:<br \/>\nr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 .<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 ..<br \/>\n.r-xr-xr-x root root 5.6 KB Fri Aug 9 10:47:26 2019 \uf15c English.txt<br \/>\n.r-xr-xr-x root root 6.6 KB Fri Aug 9 10:47:26 2019 \uf15c French.txt<br \/>\n.r-xr-xr-x root root 6.2 KB Fri Aug 9 10:47:26 2019 \uf15c German.txt<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 Ico<br \/>\n.r-xr-xr-x root root 6.2 KB Fri Aug 9 10:47:26 2019 \uf15c Italian.txt<br \/>\n.r-xr-xr-x root root 512 B Fri Aug 9 10:47:26 2019 \uf016 license.bin<br \/>\n.r-xr-xr-x root root 160 KB Fri Aug 9 10:47:26 2019 \uf016 odbccp32.dll<br \/>\n.r-xr-xr-x root root 7.1 KB Fri Aug 9 10:47:26 2019 \uf15c Spanish.txt<br \/>\n.r-xr-xr-x root root 4.9 MB Wed Apr 1 09:28:53 2020 \uf17a VerbatimSecure.exe<\/p>\n<p dir=\"ltr\">\/mnt\/Windows\/Ico:<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 .<br \/>\ndr-xr-xr-x root root 2.0 KB Wed Apr 1 09:29:50 2020 \uf115 ..<br \/>\n.r-xr-xr-x root root 34 KB Fri Aug 9 10:47:26 2019 \uf1c5 Verbatim.ico<\/p>\n<p dir=\"ltr\">By manipulating this ISO-9660 image or replacing it with another one, an<br \/>\nattacker is able to store malicious software on the emulated CD-ROM<br \/>\ndrive which then may get executed by an unsuspecting victim when using<br \/>\nthe device.<\/p>\n<p dir=\"ltr\">For example, an attacker with temporary physical access during the<br \/>\nsupply could program a modified ISO-9660 image on the Verbatim Executive<br \/>\nFingerprint Secure SSD, which always uses an attacker-controlled<br \/>\npassword for unlocking the device.<\/p>\n<p dir=\"ltr\">If, later on, the attacker gains access to the used USB drive, he can<br \/>\nsimply decrypt all contained user data.<\/p>\n<p dir=\"ltr\">Storing arbitrary other malicious software is also possible.<\/p>\n<p dir=\"ltr\">~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p dir=\"ltr\">Proof of Concept (PoC):<\/p>\n<p dir=\"ltr\">SySS could successfully modify the content of the ISO-9660 image<br \/>\ncontaining the Windows and macOS software for unlocking and managing the<br \/>\nVerbatim Executive Fingerprint Secure SSD.<\/p>\n<p dir=\"ltr\">~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p dir=\"ltr\">Solution:<\/p>\n<p dir=\"ltr\">SySS GmbH is not aware of a solution for the described security issue.<\/p>\n<p dir=\"ltr\">~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p dir=\"ltr\">Disclosure Timeline:<\/p>\n<p dir=\"ltr\">2022-02-03: Vulnerability reported to manufacturer<br \/>\n2022-02-11: Vulnerability reported to manufacturer again<br \/>\n2022-03-07: Vulnerability reported to manufacturer again<br \/>\n2022-06-08: Public release of security advisory<\/p>\n<p dir=\"ltr\">~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p dir=\"ltr\">References:<\/p>\n<p dir=\"ltr\">[1] Product website for Verbatim Executive Fingerprint Secure SSD<\/p>\n<p dir=\"ltr\">https:\/\/www.verbatim-europe.co.uk\/en\/prod\/executive-fingerprint-secure-ssd-usb-32-gen-1&#8211;usb-c-1tb-53657\/<br \/>\n[2] SySS Security Advisory SYSS-2022-013<\/p>\n<p dir=\"ltr\">https:\/\/www.syss.de\/fileadmin\/dokumente\/Publikationen\/Advisories\/SYSS-2022-013.txt<br \/>\n[3] SySS GmbH, SySS Responsible Disclosure Policy<br \/>\nhttps:\/\/www.syss.de\/en\/responsible-disclosure-policy<\/p>\n<p dir=\"ltr\">~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p dir=\"ltr\">Credits:<\/p>\n<p dir=\"ltr\">This security vulnerability was found by Matthias Deeg of SySS GmbH.<\/p>\n<p dir=\"ltr\">E-Mail: matthias.deeg (at) syss.de<br \/>\nPublic Key:<br \/>\nhttps:\/\/www.syss.de\/fileadmin\/dokumente\/Materialien\/PGPKeys\/Matthias_Deeg.asc<br \/>\nKey fingerprint = D1F0 A035 F06C E675 CDB9 0514 D9A4 BF6A 34AD 4DAB<\/p>\n<p dir=\"ltr\">~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p dir=\"ltr\">Disclaimer:<\/p>\n<p dir=\"ltr\">The information provided in this security advisory is provided &#8220;as is&#8221;<br \/>\nand without warranty of any kind. Details of this security advisory may<br \/>\nbe updated in order to provide as accurate information as possible. The<br \/>\nlatest version of this security advisory is available on the SySS website.<\/p>\n<p dir=\"ltr\">~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p dir=\"ltr\">Copyright:<\/p>\n<p dir=\"ltr\">Creative Commons &#8211; Attribution (by) &#8211; Version 3.0<br \/>\nURL: http:\/\/creativecommons.org\/licenses\/by\/3.0\/deed.en<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Advisory ID: SYSS-2022-013 Product: Executive Fingerprint Secure SSD Manufacturer: Verbatim Affected Version(s): GDMSFE01-INI3637-C VER1.1 Tested Version(s): GDMSFE01-INI3637-C VER1.1 Vulnerability Type: Insufficient Verification of Data Authenticity (CWE-345) Risk Level: Low Solution Status: Open Manufacturer Notification: 2022-02-03 Solution Date: &#8211; Public Disclosure: 2022-06-08 CVE Reference: CVE-2022-28385 Author of Advisory: Matthias Deeg (SySS GmbH) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Overview: The Verbatim &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-25979","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/25979","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=25979"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/25979\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=25979"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=25979"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=25979"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}