PT-2017-7178 · Lenovo+1 · Lenovo Thinkpad W541+1

Published

2017-11-27

·

Updated

2017-12-20

·

CVE-2015-7269

CVSS v2.0

1.9

Low

VectorAV:L/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Seagate ST500LT015 hard disk drives versions (affected versions not specified, but operating in eDrive mode on Lenovo ThinkPad W541 laptops with BIOS 2.21)
Description The issue allows physically proximate attackers to bypass self-encrypting drive (SED) protection. This can be achieved by attaching a second SATA connector to exposed pins, maintaining an alternate power source, and attaching the data cable to another machine, also known as a "Hot Unplug Attack."
Recommendations For Seagate ST500LT015 hard disk drives operating in eDrive mode on Lenovo ThinkPad W541 laptops with BIOS 2.21, consider physically securing the device to prevent unauthorized physical access, and ensure that the SATA connector and data cable are not exposed or accessible to unauthorized parties. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7269

Affected Products

Lenovo Thinkpad W541
Seagate St500Lt015