Unknown
CVE-2019-10706
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2019-10706
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- sandisk x300 sd7sb6s-128g firmware -,
- sandisk x300 sd7sb6s-256g firmware -,
- sandisk x300 sd7sb7s-010t firmware -,
- sandisk x300 sd7sb7s-512g firmware -,
- sandisk x300 sd7sf6s-128g firmware -,
- sandisk x300 sd7sf6s-256g firmware -,
- sandisk x300 sd7sf6s-512g firmware -,
- sandisk x300 sd7sn6s-128g firmware -,
- sandisk x300 sd7sn6s-256g firmware -,
- sandisk x300 sd7sn6s-512g firmware -,
- sandisk x300s sd7sb3q-064g firmware -,
- sandisk x300s sd7sn3q-064g firmware -,
- sandisk x300s sd7ub2q-010t firmware -,
- sandisk x300s sd7ub2q-512g firmware -,
- sandisk x300s sd7ub3q-128g firmware -,
- sandisk x300s sd7ub3q-256g firmware -,
- sandisk x300s sd7un3q-128g firmware -,
- sandisk x300s sd7un3q-256g firmware -,
- sandisk x300s sd7un3q-512g firmware -,
- sandisk x400 sd8sb8u-128g firmware -,
- sandisk x400 sd8sb8u-128g-1122 firmware -,
- sandisk x400 sd8sb8u-1t00 firmware -,
- sandisk x400 sd8sb8u-1t00-1122 firmware -,
- sandisk x400 sd8sb8u-256g firmware -,
- sandisk x400 sd8sb8u-256g-1122 firmware -,
- sandisk x400 sd8sb8u-512g firmware -,
- sandisk x400 sd8sb8u-512g-1122 firmware -,
- sandisk x400 sd8sn8u-128g firmware -,
- sandisk x400 sd8sn8u-128g-1122 firmware -,
- sandisk x400 sd8sn8u-1t00 firmware -,
- sandisk x400 sd8sn8u-1t00-1122 firmware -,
- sandisk x400 sd8sn8u-256g firmware -,
- sandisk x400 sd8sn8u-256g-1122 firmware -,
- sandisk x400 sd8sn8u-512g firmware -,
- sandisk x400 sd8sn8u-512g-1122 firmware -,
- sandisk x400 sd8tb8u-128g-1122 firmware -,
- sandisk x400 sd8tb8u-1t00-1122 firmware -,
- sandisk x400 sd8tb8u-256g-1122 firmware -,
- sandisk x400 sd8tb8u-512g-1122 firmware -,
- sandisk x600 sd9sb8w-128g firmware,
- sandisk x600 sd9sb8w-1t00 firmware,
- sandisk x600 sd9sb8w-256g firmware,
- sandisk x600 sd9sb8w-2t00 firmware,
- sandisk x600 sd9sb8w-512g firmware,
- sandisk x600 sd9sn8w-128g firmware,
- sandisk x600 sd9sn8w-1t00 firmware,
- sandisk x600 sd9sn8w-256g firmware,
- sandisk x600 sd9sn8w-2t00 firmware,
- sandisk x600 sd9sn8w-512g firmware,
- sandisk x600 sd9tb8w-128g firmware,
- sandisk x600 sd9tb8w-1t00 firmware,
- sandisk x600 sd9tb8w-256g firmware,
- sandisk x600 sd9tb8w-2t00 firmware,
- sandisk x600 sd9tb8w-512g firmware,
- sandisk x600 sd9tn8w-128g firmware,
- sandisk x600 sd9tn8w-1t00 firmware,
- sandisk x600 sd9tn8w-256g firmware,
- sandisk x600 sd9tn8w-2t00 firmware,
- sandisk x600 sd9tn8w-512g firmware
Weaknesses
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: