CVE-1999-1174

Executive Summary

CVE-1999-1174 exposes a flaw in Iomega ZIP-100 drives that allows an attacker with physical access to bypass disk password protection. By inserting a known disk with a known password, waiting for the drive to power down, swapping in the target disk, and reusing the known password, the attacker can access the target disk’s data without authorization. This vulnerability enables unauthorized data access on legacy storage devices.


Authoritative CVE Metadata - CVSS Base Score: 4.6 (MEDIUM) - Published: 2001-12-21T05:00:00.000 - Last Modified: 2026-09-25T20:10:00.123

Original Description: ZIP drive for Iomega ZIP-100 disks allows attackers with physical access to the drive to bypass password protection by inserting a known disk with a known password, waiting for the ZIP drive to power down, manually replacing the known disk with the target disk, and using the known password to access the target disk.

"Edison failed 10,000 times before he made the electric light. Do not be discouraged if you fail a few times."

— Napoleon Hill
Source: NVD