Summary
Detail | |||
---|---|---|---|
Vendor | Westerndigital | First view | 2020-03-10 |
Product | Sandisk x300 Sd7Sb7S-512g Firmware | Last view | 2020-03-10 |
Version | Type | Os | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
CPE Name | Affected CVE |
---|---|
cpe:2.3:o:westerndigital:sandisk_x300_sd7sb7s-512g_firmware:-:*:*:*:*:*:*:* | 2 |
Related : CVE
Date | Alert | Description | |
---|---|---|---|
5.5 | 2020-03-10 | CVE-2019-11686 | Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the drive media after their intended erasure. |
6.3 | 2020-03-10 | CVE-2019-10706 | Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
100% (2) | CWE-522 | Insufficiently Protected Credentials |