Cryptographic Weakness in Samsung and Crucial SSDs
CVE-2018-12037

4MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
20 November 2018

Summary

A cryptographic vulnerability has been identified in specific Samsung and Crucial SSD models, where a lack of a secure connection between the user password and the Disk Encryption Key allows attackers with privileged access to the SSD firmware to gain full access to encrypted data. This issue is specifically present in Samsung 840 EVO and 850 EVO devices operating in 'ATA high' mode, as well as in Samsung T3 and T5 portable drives, and the Crucial MX100, MX200, and MX300 series. Devices operating in 'TCG' or 'ATA max' mode are not affected.

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.