CVE-2015-7269 Information
Feb 14, 2021
cve
Description
Seagate ST500LT015 hard disk drives when operating in eDrive mode on Lenovo ThinkPad W541 laptops with BIOS 2.21 allow physically proximate attackers to bypass self-encrypting drive (SED) protection by attaching a second SATA connector to exposed pins maintaining an alternate power source and attaching the data cable to another machine aka a \Hot Unplug Attack.\
CVSS Vector
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://www.blackhat.com/docs/eu-15/materials/eu-15-Boteanu-Bypassing-Self-Encrypting-Drives-SED-In-Enterprise-Environments-wp.pdf https://www.infoworld.com/article/3004913/encryption/self-encrypting-drives-are-hardly-any-better-than-software-based-encryption.html
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
4.2
Share on: