4

CVE-2018-12037

An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA max" mode), Samsung T3 and T5 portable drives, and Crucial MX100, MX200 and MX300 devices. Absence of a cryptographic link between the password and the Disk Encryption Key allows attackers with privileged access to SSD firmware full access to encrypted data.

Data is provided by the National Vulnerability Database (NVD)
Samsung840 Evo Firmware Version-
   Samsung840 Evo Version-
Samsung850 Evo Firmware Version-
   Samsung850 Evo Version-
SamsungT3 Firmware Version-
   SamsungT3 Version-
SamsungT5 Firmware Version-
   SamsungT5 Version-
MicronCrucial Mx100 Firmware Version-
   MicronCrucial Mx100 Version-
MicronCrucial Mx200 Firmware Version-
   MicronCrucial Mx200 Version-
MicronCrucial Mx300 Firmware Version-
   MicronCrucial Mx300 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.15% 0.367
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4 0.4 3.6
CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 1.9 3.4 2.9
AV:L/AC:M/Au:N/C:P/I:N/A:N