CVE-2019-10706 Information

Description

Western Digital SanDisk SanDisk X300 X300s X400 and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device and if extracted could be used to install arbitrary firmware to other devices.

CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H

Reference

https://support.wdc.com/cat_products.aspx?ID=6&lang=en https://www.westerndigital.com/support/productsecurity/wdc-19006-sandisk-x600-sata-ssd https://www.westerndigital.com/support/productsecurity/wdc-19007-sandisk-x300-x400-sata-ssd

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

HIGH

Base Severity

6.3

Share on: