ID

VAR-201906-1091


CVE

CVE-2019-10636


TITLE

Self-encrypting hard drives do not adequately protect data

Trust: 0.8

sources: CERT/CC: VU#395981

DESCRIPTION

There are multiple vulnerabilities in implementations of ATA Security or TCG Opal Standards in Self-Encrypting Disks (SEDs), which can allow an attacker to decrypt contents of an encrypted drive. Marvell SSD Controller Contains vulnerabilities related to security features.Information may be tampered with. Marvell SSD Controller 88SS1074 is a solid-state hard drive controller from Marvell. This vulnerability is due to the lack of security measures such as authentication, access control, and rights management in network systems or products

Trust: 1.53

sources: CERT/CC: VU#395981 // JVNDB: JVNDB-2019-005130 // VULHUB: VHN-142202

AFFECTED PRODUCTS

vendor:marvellmodel:88ss1080scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss1087scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss1085scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss1100scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss1092scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss9188scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss9174scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss9175scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss1074scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss9189scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss1098scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss1095scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss1088scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss1093scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss1090scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss1079scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss1084scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss9187scope:eqversion: -

Trust: 1.0

vendor:marvellmodel:88ss9190scope:eqversion: -

Trust: 1.0

vendor:lenovomodel: - scope: - version: -

Trust: 0.8

vendor:micronmodel: - scope: - version: -

Trust: 0.8

vendor:microsoftmodel: - scope: - version: -

Trust: 0.8

vendor:samsung semiconductormodel: - scope: - version: -

Trust: 0.8

vendor:sandiskmodel: - scope: - version: -

Trust: 0.8

vendor:western digitalmodel: - scope: - version: -

Trust: 0.8

vendor:marvellmodel:88ss1074scope: - version: -

Trust: 0.8

vendor:marvellmodel:88ss1079scope: - version: -

Trust: 0.8

vendor:marvellmodel:88ss1080scope: - version: -

Trust: 0.8

vendor:marvellmodel:88ss1092scope: - version: -

Trust: 0.8

vendor:marvellmodel:88ss1093scope: - version: -

Trust: 0.8

vendor:marvellmodel:88ss1095scope: - version: -

Trust: 0.8

vendor:marvellmodel:88ss9174scope: - version: -

Trust: 0.8

vendor:marvellmodel:88ss9175scope: - version: -

Trust: 0.8

vendor:marvellmodel:88ss9187scope: - version: -

Trust: 0.8

vendor:marvellmodel:88ss9188scope: - version: -

Trust: 0.8

sources: CERT/CC: VU#395981 // JVNDB: JVNDB-2019-005130 // NVD: CVE-2019-10636

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-10636
value: MEDIUM

Trust: 1.0

NVD: CVE-2019-10636
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201906-064
value: MEDIUM

Trust: 0.6

VULHUB: VHN-142202
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2019-10636
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:N/I:C/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-142202
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:N/I:C/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-10636
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 0.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-142202 // JVNDB: JVNDB-2019-005130 // CNNVD: CNNVD-201906-064 // NVD: CVE-2019-10636

PROBLEMTYPE DATA

problemtype:CWE-400

Trust: 1.1

problemtype:CWE-254

Trust: 0.9

sources: VULHUB: VHN-142202 // JVNDB: JVNDB-2019-005130 // NVD: CVE-2019-10636

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201906-064

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-005130

PATCH

title:Security Advisoryurl:https://www.marvell.com/documents/x9g4hrszt5ls3udbe1eo/

Trust: 0.8

sources: JVNDB: JVNDB-2019-005130

EXTERNAL IDS

db:NVDid:CVE-2019-10636

Trust: 2.5

db:LENOVOid:LEN-25256

Trust: 1.4

db:CERT/CCid:VU#395981

Trust: 0.8

db:JVNDBid:JVNDB-2019-005130

Trust: 0.8

db:CNNVDid:CNNVD-201906-064

Trust: 0.7

db:VULHUBid:VHN-142202

Trust: 0.1

sources: CERT/CC: VU#395981 // VULHUB: VHN-142202 // JVNDB: JVNDB-2019-005130 // CNNVD: CNNVD-201906-064 // NVD: CVE-2019-10636

REFERENCES

url:https://www.westerndigital.com/support/productsecurity/wdc-19006-sandisk-x600-sata-ssd

Trust: 2.4

url:https://support.lenovo.com/us/en/product_security/len-25256

Trust: 2.2

url:https://www.marvell.com/documents/x9g4hrszt5ls3udbe1eo/

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2019-10636

Trust: 1.4

url:https://www.ru.nl/english/news-agenda/news/vm/icis/cyber-security/2018/radboud-university-researchers-discover-security/

Trust: 0.8

url:https://www.ru.nl/publish/pages/909282/draft-paper.pdf

Trust: 0.8

url:https://www.ncsc.nl/dienstverlening/response-op-dreigingen-en-incidenten/beveiligingsadviezen/ncsc-2018-0984+1.00+meerdere+kwetsbaarheden+ontdekt+in+implementaties+self-encrypting+drives.html

Trust: 0.8

url:https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/adv180028

Trust: 0.8

url:https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/jj679890(v=ws.11)#configure-use-of-hardware-based-encryption-for-fixed-data-drives

Trust: 0.8

url:https://www.samsung.com/semiconductor/minisite/ssd/support/consumer-notice/

Trust: 0.8

url:https://www.crucial.com/usa/en/support-ssd-firmware/

Trust: 0.8

url:https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings#bkmk-hdefxd

Trust: 0.8

url:https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings#bkmk-hdeosd

Trust: 0.8

url:https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings#bkmk-hderdd

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-10636

Trust: 0.8

sources: CERT/CC: VU#395981 // VULHUB: VHN-142202 // JVNDB: JVNDB-2019-005130 // CNNVD: CNNVD-201906-064 // NVD: CVE-2019-10636

SOURCES

db:CERT/CCid:VU#395981
db:VULHUBid:VHN-142202
db:JVNDBid:JVNDB-2019-005130
db:CNNVDid:CNNVD-201906-064
db:NVDid:CVE-2019-10636

LAST UPDATE DATE

2024-11-23T22:17:16.503000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#395981date:2019-11-14T00:00:00
db:VULHUBid:VHN-142202date:2020-08-24T00:00:00
db:JVNDBid:JVNDB-2019-005130date:2019-06-17T00:00:00
db:CNNVDid:CNNVD-201906-064date:2020-10-28T00:00:00
db:NVDid:CVE-2019-10636date:2024-11-21T04:19:38.300

SOURCES RELEASE DATE

db:CERT/CCid:VU#395981date:2018-11-06T00:00:00
db:VULHUBid:VHN-142202date:2019-06-04T00:00:00
db:JVNDBid:JVNDB-2019-005130date:2019-06-17T00:00:00
db:CNNVDid:CNNVD-201906-064date:2019-06-04T00:00:00
db:NVDid:CVE-2019-10636date:2019-06-04T21:29:00.733