Description
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.
Published: 2026-09-02
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authentication bypass in Phison PS3111‑S11 controller firmware versions up to SBFQT1.3. The firmware fails to enforce authentication or uses a weak CRC‑16 based handshake for privileged vendor unique commands. This allows an attacker to read or write controller memory and raw flash, persisting implants across power cycles. The weakness is classified as CWE‑306, leading to unauthorized access of firmware data and potential remote code execution or tampering of storage contents.

Affected Systems

Affected systems are devices using Phison Electronics Corporation PS3111‑S11 controller firmware versions up to SBFQT1.3. Any storage subsystem incorporating this controller that is exposed to the ATA interface is vulnerable.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity. EPSS data is not available, so current exploitation likelihood cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the ATA interface, which may be accessible locally via a SATA or USB cable. If an attacker can connect to the controller via this interface, they can exploit the unauthenticated vendor commands, read/write memory, and install persistent implants. The consequence is complete loss of data integrity and confidentiality, as well as potential compromise of system control, since the attacker can modify firmware and memory structures.

Generated by OpenCVE AI on September 2, 2026 at 03:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the installed PS3111‑S11 firmware revision; if it is SBFQT1.3 or earlier, update the controller firmware to a version that includes the authentication fix (e.g., SBFQT1.4 or later).
  • Restrict ATA interface access by disabling vendor unique command support or enabling stricter command filtering on the storage subsystem, thereby preventing unauthorized read/writes over the channel.
  • Enforce physical security controls and monitor ATA traffic for anomalous vendor unique command usage; if such traffic is detected, isolate the device for further investigation.

Generated by OpenCVE AI on September 2, 2026 at 03:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Description Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.
Title Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique Commands
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-02T00:37:52.342Z

Reserved: 2026-09-01T23:24:17.537Z

Link: CVE-2026-84696

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T01:17:24.560

Modified: 2026-09-02T01:17:24.560

Link: CVE-2026-84696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:00:09Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function