PT-2026-84575 · Phison · Ps3111-S11
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Phison PS3111-S11 controller firmware versions through SBFQT1.3
Description
Privileged vendor unique commands are exposed over the ATA interface due to absent or defeatable authentication mechanisms. This allows attackers to bypass the weak CRC-16 based unlock handshake or exploit builds that lack a VUC lock to read and write controller memory and raw flash, enabling the persistence of implants across power cycles.
Recommendations
Update Phison PS3111-S11 controller firmware to a version later than SBFQT1.3.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ps3111-S11