Vulnerability Description
Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication credentials.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Westerndigital | Sandisk X600 Sd9Tb8W-128G Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tb8W-128G | - |
| Westerndigital | Sandisk X600 Sd9Tb8W-256G Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tb8W-256G | - |
| Westerndigital | Sandisk X600 Sd9Tb8W-512G Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tb8W-512G | - |
| Westerndigital | Sandisk X600 Sd9Tb8W-1T00 Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tb8W-1T00 | - |
| Westerndigital | Sandisk X600 Sd9Tb8W-2T00 Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tb8W-2T00 | - |
| Westerndigital | Sandisk X600 Sd9Tn8W-128G Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tn8W-128G | - |
| Westerndigital | Sandisk X600 Sd9Tn8W-256G Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tn8W-256G | - |
| Westerndigital | Sandisk X600 Sd9Tn8W-512G Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tn8W-512G | - |
| Westerndigital | Sandisk X600 Sd9Tn8W-1T00 Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tn8W-1T00 | - |
| Westerndigital | Sandisk X600 Sd9Tn8W-2T00 Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tn8W-2T00 | - |
Related Weaknesses (CWE)
References
- https://support.wdc.com/cat_products.aspx?ID=6&lang=enProductVendor Advisory
- https://www.westerndigital.com/support/productsecurity/wdc-19006-sandisk-x600-saVendor Advisory
- https://www.westerndigital.com/support/productsecurity/wdc-19007-sandisk-x300-x4Not Applicable
- https://support.wdc.com/cat_products.aspx?ID=6&lang=enProductVendor Advisory
- https://www.westerndigital.com/support/productsecurity/wdc-19006-sandisk-x600-saVendor Advisory
- https://www.westerndigital.com/support/productsecurity/wdc-19007-sandisk-x300-x4Not Applicable
FAQ
What is CVE-2019-10705?
CVE-2019-10705 is a vulnerability with a CVSS score of 7.5 (HIGH). Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication c...
How severe is CVE-2019-10705?
CVE-2019-10705 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10705?
Check the references section above for vendor advisories and patch information. Affected products include: Westerndigital Sandisk X600 Sd9Tb8W-128G Firmware, Westerndigital Sandisk X600 Sd9Tb8W-128G, Westerndigital Sandisk X600 Sd9Tb8W-256G Firmware, Westerndigital Sandisk X600 Sd9Tb8W-256G, Westerndigital Sandisk X600 Sd9Tb8W-512G Firmware.