PT-2026-83780 · Phison · Ps3111-S11
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Phison PS3111-S11 controller firmware (affected versions not specified)
Description
The firmware verifies RSA signatures using a public modulus embedded within the firmware image instead of using one anchored in immutable storage. This allows an attacker to generate arbitrary RSA key pairs, sign modified firmware with the private key, and embed the corresponding modulus in the signature segment, leading the controller to accept the tampered firmware as valid.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ps3111-S11