PT-2020-13685 · Western Digital · Western Digital Inand
Brian Mastenbrook
+1
·
Published
2020-11-18
·
Updated
2026-06-05
·
CVE-2020-13799
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Western Digital iNAND devices through 2020-06-03
Description
A security issue has been identified in the Replay Protected Memory Block (RPMB) protocol, which is used by storage devices to secure trusted firmware. This issue can be exploited in several scenarios, potentially allowing an attacker to affect the RPMB state without the knowledge of the trusted component. The issue can lead to authentication bypass via a capture-replay attack.
Recommendations
For Western Digital iNAND devices through 2020-06-03, as a temporary workaround, consider restricting access to the RPMB feature until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Western Digital Inand