First published: Thu Nov 16 2017(Updated: )
SanDisk Secure Access 3.01 vault decrypts and copies encrypted files to a temporary folder, where they can remain indefinitely in certain situations, such as if the file is being edited when the user exits the application or if the application crashes.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sandisk Secureaccess | =3.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16560 is a vulnerability in SanDisk Secure Access 3.01 that allows plain text copies of encrypted files to be stored on the disk.
The severity of CVE-2017-16560 is medium with a CVSS score of 4.3.
CVE-2017-16560 affects SanDisk Secure Access 3.01 by allowing encrypted files to be decrypted and copied to a temporary folder, where they can remain indefinitely.
There is currently no fix available for CVE-2017-16560. It is recommended to avoid using SanDisk Secure Access 3.01 or to use alternative secure file storage solutions.
More information about CVE-2017-16560 can be found at https://medium.com/@esterling_/cve-2017-16560-sandisk-secure-access-leaves-plain-text-copies-of-files-on-disk-4eabeca6bdbc.