Vulnerability Description
An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA max" mode), Samsung T3 and T5 portable drives, and Crucial MX100, MX200 and MX300 devices. Absence of a cryptographic link between the password and the Disk Encryption Key allows attackers with privileged access to SSD firmware full access to encrypted data.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samsung | 840 Evo Firmware | - |
| Samsung | 840 Evo | - |
| Samsung | 850 Evo Firmware | - |
| Samsung | 850 Evo | - |
| Samsung | T3 Firmware | - |
| Samsung | T3 | - |
| Samsung | T5 Firmware | - |
| Samsung | T5 | - |
| Micron | Crucial Mx100 Firmware | - |
| Micron | Crucial Mx100 | - |
| Micron | Crucial Mx200 Firmware | - |
| Micron | Crucial Mx200 | - |
| Micron | Crucial Mx300 Firmware | - |
| Micron | Crucial Mx300 | - |
References
- http://www.securityfocus.com/bid/105840Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180028PatchThird Party AdvisoryVendor Advisory
- https://security.netapp.com/advisory/ntap-20181112-0001/Third Party Advisory
- http://www.securityfocus.com/bid/105840Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180028PatchThird Party AdvisoryVendor Advisory
- https://security.netapp.com/advisory/ntap-20181112-0001/Third Party Advisory
FAQ
What is CVE-2018-12037?
CVE-2018-12037 is a vulnerability with a CVSS score of 4.0 (MEDIUM). An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA max" mode), Samsung T3 and T5 portable drives, and Crucial MX100, MX200 and MX3...
How severe is CVE-2018-12037?
CVE-2018-12037 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-12037?
Check the references section above for vendor advisories and patch information. Affected products include: Samsung 840 Evo Firmware, Samsung 840 Evo, Samsung 850 Evo Firmware, Samsung 850 Evo, Samsung T3 Firmware.