Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-2500 Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T22:32:01.181Z

Reserved: 2019-04-02T00:00:00

Link: CVE-2019-10706

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-10T13:15:12.500

Modified: 2024-11-21T04:19:46.387

Link: CVE-2019-10706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.