CVE-2019-10706 Information
Feb 14, 2021
cve
Description
Western Digital SanDisk SanDisk X300 X300s X400 and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device and if extracted could be used to install arbitrary firmware to other devices.
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Reference
https://support.wdc.com/cat_products.aspx?ID=6&lang=en https://www.westerndigital.com/support/productsecurity/wdc-19006-sandisk-x600-sata-ssd https://www.westerndigital.com/support/productsecurity/wdc-19007-sandisk-x300-x400-sata-ssd
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
HIGH
Base Severity
6.3
Share on: