1.9
CVSSv2

CVE-2018-12037

Published: 20/11/2018 Updated: 03/10/2019
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 4 | Impact Score: 3.6 | Exploitability Score: 0.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA max" mode), Samsung T3 and T5 portable drives, and Crucial MX100, MX200 and MX300 devices. Absence of a cryptographic link between the password and the Disk Encryption Key allows attackers with privileged access to SSD firmware full access to encrypted data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samsung 840_evo_firmware -

samsung 850_evo_firmware -

samsung t3_firmware -

samsung t5_firmware -

micron crucial_mx100_firmware -

micron crucial_mx200_firmware -

micron crucial_mx300_firmware -