An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is stored in CANVIO PREMIUM 3TB(HD-MB30TY, HD-MA30TY, HD-MB30TS, HD-MA30TS), CANVIO PREMIUM 2TB(HD-MB20TY, HD-MA20TY, HD-MB20TS, HD-MA20TS), CANVIO PREMIUM 1TB(HD-MB10TY, HD-MA10TY, HD-MB10TS, HD-MA10TS), CANVIO SLIM 1TB(HD-SB10TK, HD-SB10TS), and CANVIO SLIM 500GB(HD-SB50GK, HD-SA50GK, HD-SB50GS, HD-SA50GS), and which was downloaded before 2020 May 10. Since it registers Windows services with unquoted file paths, when a registered path contains spaces, and a malicious executable is placed on a certain path, it may be executed with the privilege of the Windows service.

Project Subscriptions

Vendors Products
Toshiba Subscribe
Hd-ma10ts Subscribe
Hd-ma10ty Subscribe
Hd-ma20ts Subscribe
Hd-ma20ty Subscribe
Hd-ma30ts Subscribe
Hd-ma30ty Subscribe
Hd-mb10ts Subscribe
Hd-mb10ty Subscribe
Hd-mb20ts Subscribe
Hd-mb20ty Subscribe
Hd-mb30ts Subscribe
Hd-mb30ty Subscribe
Hd-sa50gk Subscribe
Hd-sa50gs Subscribe
Hd-sb10tk Subscribe
Hd-sb10ts Subscribe
Hd-sb50gk Subscribe
Hd-sb50gs Subscribe
Password Tool For Windows Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-26731 An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is stored in CANVIO PREMIUM 3TB(HD-MB30TY, HD-MA30TY, HD-MB30TS, HD-MA30TS), CANVIO PREMIUM 2TB(HD-MB20TY, HD-MA20TY, HD-MB20TS, HD-MA20TS), CANVIO PREMIUM 1TB(HD-MB10TY, HD-MA10TY, HD-MB10TS, HD-MA10TS), CANVIO SLIM 1TB(HD-SB10TK, HD-SB10TS), and CANVIO SLIM 500GB(HD-SB50GK, HD-SA50GK, HD-SB50GS, HD-SA50GS), and which was downloaded before 2020 May 10. Since it registers Windows services with unquoted file paths, when a registered path contains spaces, and a malicious executable is placed on a certain path, it may be executed with the privilege of the Windows service.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-08-04T08:30:24.635Z

Reserved: 2020-01-06T00:00:00

Link: CVE-2020-5569

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-20T08:15:15.130

Modified: 2024-11-21T05:34:17.387

Link: CVE-2020-5569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses