Impact
The vulnerability is an authentication bypass in Phison PS3111‑S11 controller firmware versions up to SBFQT1.3. The firmware fails to enforce authentication or uses a weak CRC‑16 based handshake for privileged vendor unique commands. This allows an attacker to read or write controller memory and raw flash, persisting implants across power cycles. The weakness is classified as CWE‑306, leading to unauthorized access of firmware data and potential remote code execution or tampering of storage contents.
Affected Systems
Affected systems are devices using Phison Electronics Corporation PS3111‑S11 controller firmware versions up to SBFQT1.3. Any storage subsystem incorporating this controller that is exposed to the ATA interface is vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. EPSS data is not available, so current exploitation likelihood cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the ATA interface, which may be accessible locally via a SATA or USB cable. If an attacker can connect to the controller via this interface, they can exploit the unauthenticated vendor commands, read/write memory, and install persistent implants. The consequence is complete loss of data integrity and confidentiality, as well as potential compromise of system control, since the attacker can modify firmware and memory structures.
OpenCVE Enrichment