Vulnerability Description
Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the drive media after their intended erasure.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Westerndigital | Sandisk X600 Sd9Tb8W-128G Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tb8W-128G | - |
| Westerndigital | Sandisk X600 Sd9Tb8W-256G Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tb8W-256G | - |
| Westerndigital | Sandisk X600 Sd9Tb8W-512G Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tb8W-512G | - |
| Westerndigital | Sandisk X600 Sd9Tb8W-1T00 Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tb8W-1T00 | - |
| Westerndigital | Sandisk X600 Sd9Tb8W-2T00 Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tb8W-2T00 | - |
| Westerndigital | Sandisk X600 Sd9Tn8W-128G Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tn8W-128G | - |
| Westerndigital | Sandisk X600 Sd9Tn8W-256G Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tn8W-256G | - |
| Westerndigital | Sandisk X600 Sd9Tn8W-512G Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tn8W-512G | - |
| Westerndigital | Sandisk X600 Sd9Tn8W-1T00 Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tn8W-1T00 | - |
| Westerndigital | Sandisk X600 Sd9Tn8W-2T00 Firmware | < x6112100 |
| Westerndigital | Sandisk X600 Sd9Tn8W-2T00 | - |
Related Weaknesses (CWE)
References
- https://support.wdc.com/downloads.aspx?g=907&lang=enNot Applicable
- https://www.westerndigital.com/support/productsecurity/wdc-19006-sandisk-x600-saVendor Advisory
- https://www.westerndigital.com/support/productsecurity/wdc-19007-sandisk-x300-x4Broken Link
- https://support.wdc.com/downloads.aspx?g=907&lang=enNot Applicable
- https://www.westerndigital.com/support/productsecurity/wdc-19006-sandisk-x600-saVendor Advisory
- https://www.westerndigital.com/support/productsecurity/wdc-19007-sandisk-x300-x4Broken Link
FAQ
What is CVE-2019-11686?
CVE-2019-11686 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys)...
How severe is CVE-2019-11686?
CVE-2019-11686 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-11686?
Check the references section above for vendor advisories and patch information. Affected products include: Westerndigital Sandisk X600 Sd9Tb8W-128G Firmware, Westerndigital Sandisk X600 Sd9Tb8W-128G, Westerndigital Sandisk X600 Sd9Tb8W-256G Firmware, Westerndigital Sandisk X600 Sd9Tb8W-256G, Westerndigital Sandisk X600 Sd9Tb8W-512G Firmware.