CVE-2018-12037
An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA max" mode), Samsung T3 and T5 portable drives, and Crucial MX100, MX200 and MX300 devices. Absence of a cryptographic link between the password and the Disk Encryption Key allows attackers with privileged access to SSD firmware full access to encrypted data.
Published:Nov 20, 2018
Last Modified:Nov 21, 2024
EPS:Nov 20, 2018
EPSS Score:0.00154
CVSS Score:4
Affected Products
Vendor
Product
Action
Vendor
Micron
Product
Crucial Mx100
Micron
Crucial Mx100
Vendor
Micron
Product
Crucial Mx100 Firmware
Micron
Crucial Mx100 Firmware
Vendor
Micron
Product
Crucial Mx200
Micron
Crucial Mx200
Vendor
Micron
Product
Crucial Mx200 Firmware
Micron
Crucial Mx200 Firmware
Vendor
Micron
Product
Crucial Mx300
Micron
Crucial Mx300
Vendor
Micron
Product
Crucial Mx300 Firmware
Micron
Crucial Mx300 Firmware
Vendor
Samsung
Product
840 Evo
Samsung
840 Evo
Vendor
Samsung
Product
840 Evo Firmware
Samsung
840 Evo Firmware
Vendor
Samsung
Product
850 Evo
Samsung
850 Evo
Vendor
Samsung
Product
850 Evo Firmware
Samsung
850 Evo Firmware
Vendor
Samsung
Product
T3
Samsung
T3
Vendor
Samsung
Product
T3 Firmware
Samsung
T3 Firmware
Vendor
Samsung
Product
T5
Samsung
T5
Vendor
Samsung
Product
T5 Firmware
Samsung
T5 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
