Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Bernard Van Gastel

Researcher fromRadboud University, the Netherlands, Open University of the Netherlands
#19243of 53,633
13.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2020-9124
7.5
2020-03-10
Western Digital · Western Digital Sandisk X600 · CVE-2019-10705
**Name of the Vulnerable Software and Affected Versions** Western Digital SanDisk X600 devices (affected versions not specified) **Description** A vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication credentials. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2020-9125
6.3
2020-03-10
Western Digital · Sandisk X600 · CVE-2019-10706
**Name of the Vulnerable Software and Affected Versions** Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices (affected versions not specified) **Description** The firmware update authentication method in the affected devices relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device. If this key is extracted, it could be used to install arbitrary firmware on other devices. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.