Cryptographic Weakness in Samsung and Crucial SSDs
CVE-2018-12037
4MEDIUM
Summary
A cryptographic vulnerability has been identified in specific Samsung and Crucial SSD models, where a lack of a secure connection between the user password and the Disk Encryption Key allows attackers with privileged access to the SSD firmware to gain full access to encrypted data. This issue is specifically present in Samsung 840 EVO and 850 EVO devices operating in 'ATA high' mode, as well as in Samsung T3 and T5 portable drives, and the Crucial MX100, MX200, and MX300 series. Devices operating in 'TCG' or 'ATA max' mode are not affected.
References
CVSS V3.1
Score:
4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved