Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-7267

Опубликовано: 27 нояб. 2017
Источник: nvd
CVSS3: 4.2
CVSS2: 1.9
EPSS Низкий

Описание

Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS 2.32; ThinkPad W541 laptops with BIOS 2.21; Dell Latitude E6410 laptops with BIOS A16; or Latitude E6430 laptops with BIOS A16, allow physically proximate attackers to bypass self-encrypting drive (SED) protection by leveraging failure to detect when SATA drives are unplugged in Sleep Mode, aka a "Hot Plug attack."

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:samsung:850_pro_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:850_pro:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:samsung:pm851_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:pm851:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:seagate:st500lt015_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:seagate:st500lt015:-:*:*:*:*:*:*:*
Конфигурация 4

Одновременно

cpe:2.3:o:seagate:st500lt025_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:seagate:st500lt025:-:*:*:*:*:*:*:*

EPSS

Процентиль: 18%
0.00059
Низкий

4.2 Medium

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-254

Связанные уязвимости

CVSS3: 4.2
github
больше 3 лет назад

Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS 2.32; ThinkPad W541 laptops with BIOS 2.21; Dell Latitude E6410 laptops with BIOS A16; or Latitude E6430 laptops with BIOS A16, allow physically proximate attackers to bypass self-encrypting drive (SED) protection by leveraging failure to detect when SATA drives are unplugged in Sleep Mode, aka a "Hot Plug attack."

EPSS

Процентиль: 18%
0.00059
Низкий

4.2 Medium

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-254