HIGH · 7.5

CVE-2019-10705

Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication c...

Vulnerability Description

Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication credentials.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
WesterndigitalSandisk X600 Sd9Tb8W-128G Firmware< x6112100
WesterndigitalSandisk X600 Sd9Tb8W-128G-
WesterndigitalSandisk X600 Sd9Tb8W-256G Firmware< x6112100
WesterndigitalSandisk X600 Sd9Tb8W-256G-
WesterndigitalSandisk X600 Sd9Tb8W-512G Firmware< x6112100
WesterndigitalSandisk X600 Sd9Tb8W-512G-
WesterndigitalSandisk X600 Sd9Tb8W-1T00 Firmware< x6112100
WesterndigitalSandisk X600 Sd9Tb8W-1T00-
WesterndigitalSandisk X600 Sd9Tb8W-2T00 Firmware< x6112100
WesterndigitalSandisk X600 Sd9Tb8W-2T00-
WesterndigitalSandisk X600 Sd9Tn8W-128G Firmware< x6112100
WesterndigitalSandisk X600 Sd9Tn8W-128G-
WesterndigitalSandisk X600 Sd9Tn8W-256G Firmware< x6112100
WesterndigitalSandisk X600 Sd9Tn8W-256G-
WesterndigitalSandisk X600 Sd9Tn8W-512G Firmware< x6112100
WesterndigitalSandisk X600 Sd9Tn8W-512G-
WesterndigitalSandisk X600 Sd9Tn8W-1T00 Firmware< x6112100
WesterndigitalSandisk X600 Sd9Tn8W-1T00-
WesterndigitalSandisk X600 Sd9Tn8W-2T00 Firmware< x6112100
WesterndigitalSandisk X600 Sd9Tn8W-2T00-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-10705?

CVE-2019-10705 is a vulnerability with a CVSS score of 7.5 (HIGH). Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication c...

How severe is CVE-2019-10705?

CVE-2019-10705 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-10705?

Check the references section above for vendor advisories and patch information. Affected products include: Westerndigital Sandisk X600 Sd9Tb8W-128G Firmware, Westerndigital Sandisk X600 Sd9Tb8W-128G, Westerndigital Sandisk X600 Sd9Tb8W-256G Firmware, Westerndigital Sandisk X600 Sd9Tb8W-256G, Westerndigital Sandisk X600 Sd9Tb8W-512G Firmware.