CVE-2018-12037 Details
Description
An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA max" mode), Samsung T3 and T5 portable drives, and Crucial MX100, MX200 and MX300 devices. Absence of a cryptographic link between the password and the Disk Encryption Key allows attackers with privileged access to SSD firmware full access to encrypted data.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180028 | CVE | PatchThird Party AdvisoryVendor Advisory |
| https://security.netapp.com/advisory/ntap-20181112-0001/ | CVE | Third Party Advisory |
| http://www.securityfocus.com/bid/105840 | CVE | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180028 | [email protected] | PatchThird Party AdvisoryVendor Advisory |
| https://security.netapp.com/advisory/ntap-20181112-0001/ | [email protected] | Third Party Advisory |
| http://www.securityfocus.com/bid/105840 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| samsung 840 evo firmware | All versions |
CPE
Remediation
| |
| samsung 840 evo | All versions |
CPE
Remediation
| |
| samsung 850 evo firmware | All versions |
CPE
Remediation
| |
| samsung 850 evo | All versions |
CPE
Remediation
| |
| samsung t3 firmware | All versions |
CPE
Remediation
| |
| samsung t3 | All versions |
CPE
Remediation
| |
| samsung t5 firmware | All versions |
CPE
Remediation
| |
| samsung t5 | All versions |
CPE
Remediation
| |
| micron crucial mx100 firmware | All versions |
CPE
Remediation
| |
| micron crucial mx100 | All versions |
CPE
Remediation
| |
| micron crucial mx200 firmware | All versions |
CPE
Remediation
| |
| micron crucial mx200 | All versions |
CPE
Remediation
| |
| micron crucial mx300 firmware | All versions |
CPE
Remediation
| |
| micron crucial mx300 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Dec 20, 2018 | Initial Analysis | [email protected] |
| Nov 21, 2018 | CVE Modified | [email protected] |