Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices.

Project Subscriptions

Vendors Products
Westerndigital Subscribe
Sandisk X300 Sd7sb6s-128g Subscribe
Sandisk X300 Sd7sb6s-128g Firmware Subscribe
Sandisk X300 Sd7sb6s-256g Subscribe
Sandisk X300 Sd7sb6s-256g Firmware Subscribe
Sandisk X300 Sd7sb7s-010t Subscribe
Sandisk X300 Sd7sb7s-010t Firmware Subscribe
Sandisk X300 Sd7sb7s-512g Subscribe
Sandisk X300 Sd7sb7s-512g Firmware Subscribe
Sandisk X300 Sd7sf6s-128g Subscribe
Sandisk X300 Sd7sf6s-128g Firmware Subscribe
Sandisk X300 Sd7sf6s-256g Subscribe
Sandisk X300 Sd7sf6s-256g Firmware Subscribe
Sandisk X300 Sd7sf6s-512g Subscribe
Sandisk X300 Sd7sf6s-512g Firmware Subscribe
Sandisk X300 Sd7sn6s-128g Subscribe
Sandisk X300 Sd7sn6s-128g Firmware Subscribe
Sandisk X300 Sd7sn6s-256g Subscribe
Sandisk X300 Sd7sn6s-256g Firmware Subscribe
Sandisk X300 Sd7sn6s-512g Subscribe
Sandisk X300 Sd7sn6s-512g Firmware Subscribe
Sandisk X300s Sd7sb3q-064g Subscribe
Sandisk X300s Sd7sb3q-064g Firmware Subscribe
Sandisk X300s Sd7sn3q-064g Subscribe
Sandisk X300s Sd7sn3q-064g Firmware Subscribe
Sandisk X300s Sd7ub2q-010t Subscribe
Sandisk X300s Sd7ub2q-010t Firmware Subscribe
Sandisk X300s Sd7ub2q-512g Subscribe
Sandisk X300s Sd7ub2q-512g Firmware Subscribe
Sandisk X300s Sd7ub3q-128g Subscribe
Sandisk X300s Sd7ub3q-128g Firmware Subscribe
Sandisk X300s Sd7ub3q-256g Subscribe
Sandisk X300s Sd7ub3q-256g Firmware Subscribe
Sandisk X300s Sd7un3q-128g Subscribe
Sandisk X300s Sd7un3q-128g Firmware Subscribe
Sandisk X300s Sd7un3q-256g Subscribe
Sandisk X300s Sd7un3q-256g Firmware Subscribe
Sandisk X300s Sd7un3q-512g Subscribe
Sandisk X300s Sd7un3q-512g Firmware Subscribe
Sandisk X400 Sd8sb8u-128g Subscribe
Sandisk X400 Sd8sb8u-128g-1122 Subscribe
Sandisk X400 Sd8sb8u-128g-1122 Firmware Subscribe
Sandisk X400 Sd8sb8u-128g Firmware Subscribe
Sandisk X400 Sd8sb8u-1t00 Subscribe
Sandisk X400 Sd8sb8u-1t00-1122 Subscribe
Sandisk X400 Sd8sb8u-1t00-1122 Firmware Subscribe
Sandisk X400 Sd8sb8u-1t00 Firmware Subscribe
Sandisk X400 Sd8sb8u-256g Subscribe
Sandisk X400 Sd8sb8u-256g-1122 Subscribe
Sandisk X400 Sd8sb8u-256g-1122 Firmware Subscribe
Sandisk X400 Sd8sb8u-256g Firmware Subscribe
Sandisk X400 Sd8sb8u-512g Subscribe
Sandisk X400 Sd8sb8u-512g-1122 Subscribe
Sandisk X400 Sd8sb8u-512g-1122 Firmware Subscribe
Sandisk X400 Sd8sb8u-512g Firmware Subscribe
Sandisk X400 Sd8sn8u-128g Subscribe
Sandisk X400 Sd8sn8u-128g-1122 Subscribe
Sandisk X400 Sd8sn8u-128g-1122 Firmware Subscribe
Sandisk X400 Sd8sn8u-128g Firmware Subscribe
Sandisk X400 Sd8sn8u-1t00 Subscribe
Sandisk X400 Sd8sn8u-1t00-1122 Subscribe
Sandisk X400 Sd8sn8u-1t00-1122 Firmware Subscribe
Sandisk X400 Sd8sn8u-1t00 Firmware Subscribe
Sandisk X400 Sd8sn8u-256g Subscribe
Sandisk X400 Sd8sn8u-256g-1122 Subscribe
Sandisk X400 Sd8sn8u-256g-1122 Firmware Subscribe
Sandisk X400 Sd8sn8u-256g Firmware Subscribe
Sandisk X400 Sd8sn8u-512g Subscribe
Sandisk X400 Sd8sn8u-512g-1122 Subscribe
Sandisk X400 Sd8sn8u-512g-1122 Firmware Subscribe
Sandisk X400 Sd8sn8u-512g Firmware Subscribe
Sandisk X400 Sd8tb8u-128g-1122 Subscribe
Sandisk X400 Sd8tb8u-128g-1122 Firmware Subscribe
Sandisk X400 Sd8tb8u-1t00-1122 Subscribe
Sandisk X400 Sd8tb8u-1t00-1122 Firmware Subscribe
Sandisk X400 Sd8tb8u-256g-1122 Subscribe
Sandisk X400 Sd8tb8u-256g-1122 Firmware Subscribe
Sandisk X400 Sd8tb8u-512g-1122 Subscribe
Sandisk X400 Sd8tb8u-512g-1122 Firmware Subscribe
Sandisk X600 Sd9sb8w-128g Subscribe
Sandisk X600 Sd9sb8w-128g Firmware Subscribe
Sandisk X600 Sd9sb8w-1t00 Subscribe
Sandisk X600 Sd9sb8w-1t00 Firmware Subscribe
Sandisk X600 Sd9sb8w-256g Subscribe
Sandisk X600 Sd9sb8w-256g Firmware Subscribe
Sandisk X600 Sd9sb8w-2t00 Subscribe
Sandisk X600 Sd9sb8w-2t00 Firmware Subscribe
Sandisk X600 Sd9sb8w-512g Subscribe
Sandisk X600 Sd9sb8w-512g Firmware Subscribe
Sandisk X600 Sd9sn8w-128g Subscribe
Sandisk X600 Sd9sn8w-128g Firmware Subscribe
Sandisk X600 Sd9sn8w-1t00 Subscribe
Sandisk X600 Sd9sn8w-1t00 Firmware Subscribe
Sandisk X600 Sd9sn8w-256g Subscribe
Sandisk X600 Sd9sn8w-256g Firmware Subscribe
Sandisk X600 Sd9sn8w-2t00 Subscribe
Sandisk X600 Sd9sn8w-2t00 Firmware Subscribe
Sandisk X600 Sd9sn8w-512g Subscribe
Sandisk X600 Sd9sn8w-512g Firmware Subscribe
Sandisk X600 Sd9tb8w-128g Subscribe
Sandisk X600 Sd9tb8w-128g Firmware Subscribe
Sandisk X600 Sd9tb8w-1t00 Subscribe
Sandisk X600 Sd9tb8w-1t00 Firmware Subscribe
Sandisk X600 Sd9tb8w-256g Subscribe
Sandisk X600 Sd9tb8w-256g Firmware Subscribe
Sandisk X600 Sd9tb8w-2t00 Subscribe
Sandisk X600 Sd9tb8w-2t00 Firmware Subscribe
Sandisk X600 Sd9tb8w-512g Subscribe
Sandisk X600 Sd9tb8w-512g Firmware Subscribe
Sandisk X600 Sd9tn8w-128g Subscribe
Sandisk X600 Sd9tn8w-128g Firmware Subscribe
Sandisk X600 Sd9tn8w-1t00 Subscribe
Sandisk X600 Sd9tn8w-1t00 Firmware Subscribe
Sandisk X600 Sd9tn8w-256g Subscribe
Sandisk X600 Sd9tn8w-256g Firmware Subscribe
Sandisk X600 Sd9tn8w-2t00 Subscribe
Sandisk X600 Sd9tn8w-2t00 Firmware Subscribe
Sandisk X600 Sd9tn8w-512g Subscribe
Sandisk X600 Sd9tn8w-512g Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-2500 Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T22:32:01.181Z

Reserved: 2019-04-02T00:00:00

Link: CVE-2019-10706

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-10T13:15:12.500

Modified: 2024-11-21T04:19:46.387

Link: CVE-2019-10706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses