cvedb.io
CVE-2022-28383
MEDIUM · CVSS 6.8
EPSS exploitation probability: 0%
Published 2022-06-08T16:15:08.027 · Last modified 2026-06-17T04:38:28.293

Summary

An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attacker can store malicious firmware code for the USB-to-SATA bridge controller on the USB drive (e.g., by leveraging physical access during the supply chain). This code is then executed. This affects Keypad Secure USB 3.2 Gen 1 Drive Part Number #49428, Store 'n' Go Secure Portable HDD GD25LK01-3637-C VER4.0, Executive Fingerprint Secure SSD GDMSFE01-INI3637-C VER1.1, and Fingerprint Secure Portable Hard Drive Part Number #53650.

Affected products

verbatim — keypad_secure_usb_3.2_gen_1_firmware

Does this affect you?

Add your gear to cvedb and we'll alert you only when verbatim ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.