CVE Feed

    Dashboard / CVE / CVE-2015-7267

    CVE-2015-7267

    Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS 2.32; ThinkPad W541 laptops with BIOS 2.21; Dell Latitude E6410 laptops with BIOS A16; or Latitude E6430 laptops with BIOS A16, allow physically proximate attackers to bypass self-encrypting drive (SED) protection by leveraging failure to detect when SATA drives are unplugged in Sleep Mode, aka a "Hot Plug attack."

    Published:Nov 27, 2017
    Last Modified:Apr 20, 2025
    EPS:Nov 27, 2017
    EPSS Score:0.00059
    CVSS Score:4.2

    Affected Products

    Vendor
    Samsung
    Product
    850 Pro
    Vendor
    Samsung
    Product
    850 Pro Firmware
    Vendor
    Samsung
    Product
    Pm851
    Vendor
    Samsung
    Product
    Pm851 Firmware
    Vendor
    Seagate
    Product
    St500lt015
    Vendor
    Seagate
    Product
    St500lt015 Firmware
    Vendor
    Seagate
    Product
    St500lt025
    Vendor
    Seagate
    Product
    St500lt025 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High