PT-2019-13351 · Sandisk+1 · Sandisk Ssd Dashboard+1

Publicado

2019-09-30

·

Atualizado

2020-08-24

·

CVE-2019-13466

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Western Digital SSD Dashboard versions prior to 2.5.1.0 SanDisk SSD Dashboard versions prior to 2.5.1.0
Description The issue is related to Incorrect Access Control. Specifically, the generate reports archive is protected with a hard-coded password, which poses a security risk. An update is available that addresses the protection of archive encryption.
Recommendations For Western Digital SSD Dashboard versions prior to 2.5.1.0, update to version 2.5.1.0 or later to address the issue. For SanDisk SSD Dashboard versions prior to 2.5.1.0, update to version 2.5.1.0 or later to address the issue.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-13466

Produtos afetados

Sandisk Ssd Dashboard
Western Digital Ssd Dashboard