Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-24jw-qhh7-33q6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices.

Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices.

EPSS

Процентиль: 31%
0.00116
Низкий

Связанные уязвимости

CVSS3: 6.3
nvd
больше 5 лет назад

Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices.

EPSS

Процентиль: 31%
0.00116
Низкий