PT-2018-10958 · Crucial+1 · Crucial Mx300+6
Published
2018-11-20
·
Updated
2023-10-27
·
CVE-2018-12037
CVSS v2.0
1.9
Low
| Vector | AV:L/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Samsung 840 EVO versions (affected versions not specified)
Samsung 850 EVO versions (affected versions not specified)
Samsung T3 versions (affected versions not specified)
Samsung T5 versions (affected versions not specified)
Crucial MX100 versions (affected versions not specified)
Crucial MX200 versions (affected versions not specified)
Crucial MX300 versions (affected versions not specified)
Description
An issue allows attackers with privileged access to SSD firmware full access to encrypted data due to the absence of a cryptographic link between the password and the Disk Encryption Key. This issue affects devices in "ATA high" mode.
Recommendations
For Samsung 840 EVO, consider disabling hardware encryption until a patch is available.
For Samsung 850 EVO, consider disabling hardware encryption until a patch is available.
For Samsung T3, consider disabling hardware encryption until a patch is available.
For Samsung T5, consider disabling hardware encryption until a patch is available.
For Crucial MX100, consider disabling hardware encryption until a patch is available.
For Crucial MX200, consider disabling hardware encryption until a patch is available.
For Crucial MX300, consider disabling hardware encryption until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crucial Mx100
Crucial Mx200
Crucial Mx300
Samsung 840 Evo
Samsung 850 Evo
Samsung T3
Samsung T5