Vulnerability Description
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/trulycrisp/disksec
- https://github.com/trulycrisp/psychite
- https://trulycrisp.github.io/drivefirmware/phison_s11/
- https://www.vulncheck.com/advisories/phison-ps3111-s11-controller-firmware-missi
FAQ
What is CVE-2026-84696?
CVE-2026-84696 is a vulnerability with a CVSS score of 8.2 (HIGH). Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypas...
How severe is CVE-2026-84696?
CVE-2026-84696 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-84696?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.