CVE-2020-13799 Details
Description
Western Digital has identified a security vulnerability in the Replay Protected Memory Block (RPMB) protocol as specified in multiple standards for storage device interfaces, including all versions of eMMC, UFS, and NVMe. The RPMB protocol is specified by industry standards bodies and is implemented by storage devices from multiple vendors to assist host systems in securing trusted firmware. Several scenarios have been identified in which the RPMB state may be affected by an attacker without the knowledge of the trusted component that uses the RPMB feature.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kb.cert.org/vuls/id/231329 | CVE | Third Party AdvisoryUS Government Resource |
| https://www.westerndigital.com/support/productsecurity/wdc-20008-replay-attack-vulnerabilities-rpmb-protocol-applications | CVE | Vendor Advisory |
| https://www.kb.cert.org/vuls/id/231329 | [email protected] | Third Party AdvisoryUS Government Resource |
| https://www.westerndigital.com/support/productsecurity/wdc-20008-replay-attack-vulnerabilities-rpmb-protocol-applications | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-294 | Authentication Bypass by Capture-replay | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| westerndigital inand cl em132 firmware | <= 2020-06-03 |
CPE
Remediation
| |
| westerndigital inand cl em132 | All versions |
CPE
Remediation
| |
| westerndigital inand ix em132 firmware | <= 2020-06-03 |
CPE
Remediation
| |
| westerndigital inand ix em132 | All versions |
CPE
Remediation
| |
| westerndigital inand ix em132 xi firmware | <= 2020-06-03 |
CPE
Remediation
| |
| westerndigital inand ix em132 xi | All versions |
CPE
Remediation
| |
| trustedfirmware op-tee | <= 3.11.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 5, 2026 | CPE Deprecation Remap | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jun 29, 2021 | Reanalysis | [email protected] |
| Dec 3, 2020 | Initial Analysis | [email protected] |
| Dec 1, 2020 | CVE Modified | [email protected] |