MEDIUM · 4.6

CVE-2019-10636

Marvell SSD Controller (88SS1074, 88SS1079, 88SS1080, 88SS1093, 88SS1092, 88SS1095, 88SS9174, 88SS9175, 88SS9187, 88SS9188, 88SS9189, 88SS9190, 88SS1085, 88SS1087, 88SS1090, 88SS1100, 88SS1084, 88SS10...

Vulnerability Description

Marvell SSD Controller (88SS1074, 88SS1079, 88SS1080, 88SS1093, 88SS1092, 88SS1095, 88SS9174, 88SS9175, 88SS9187, 88SS9188, 88SS9189, 88SS9190, 88SS1085, 88SS1087, 88SS1090, 88SS1100, 88SS1084, 88SS1088, & 88SS1098) devices allow reprogramming flash memory to bypass the secure boot protection mechanism.

CVSS Score

4.6

MEDIUM

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
Marvell88Ss1074 Firmware-
Marvell88Ss1074-
Marvell88Ss1079 Firmware-
Marvell88Ss1079-
Marvell88Ss1080 Firmware-
Marvell88Ss1080-
Marvell88Ss1093 Firmware-
Marvell88Ss1093-
Marvell88Ss1092 Firmware-
Marvell88Ss1092-
Marvell88Ss1095 Firmware-
Marvell88Ss1095-
Marvell88Ss9174 Firmware-
Marvell88Ss9174-
Marvell88Ss9175 Firmware-
Marvell88Ss9175-
Marvell88Ss9187 Firmware-
Marvell88Ss9187-
Marvell88Ss9188 Firmware-
Marvell88Ss9188-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-10636?

CVE-2019-10636 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Marvell SSD Controller (88SS1074, 88SS1079, 88SS1080, 88SS1093, 88SS1092, 88SS1095, 88SS9174, 88SS9175, 88SS9187, 88SS9188, 88SS9189, 88SS9190, 88SS1085, 88SS1087, 88SS1090, 88SS1100, 88SS1084, 88SS10...

How severe is CVE-2019-10636?

CVE-2019-10636 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-10636?

Check the references section above for vendor advisories and patch information. Affected products include: Marvell 88Ss1074 Firmware, Marvell 88Ss1074, Marvell 88Ss1079 Firmware, Marvell 88Ss1079, Marvell 88Ss1080 Firmware.