Lucene search

K
cveCertccCVE-2015-7269
HistoryNov 27, 2017 - 10:29 p.m.

CVE-2015-7269

2017-11-2722:29:00
CWE-254
certcc
web.nvd.nist.gov
20
cve-2015-7269
seagate
edrive mode
lenovo thinkpad w541
bios 2.21
sed protection
hot unplug attack

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

4.2

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

4.5

Confidence

High

EPSS

0.001

Percentile

30.3%

Seagate ST500LT015 hard disk drives, when operating in eDrive mode on Lenovo ThinkPad W541 laptops with BIOS 2.21, allow physically proximate attackers to bypass self-encrypting drive (SED) protection by attaching a second SATA connector to exposed pins, maintaining an alternate power source, and attaching the data cable to another machine, aka a “Hot Unplug Attack.”

Affected configurations

Nvd
Node
seagatest500lt015_firmwareMatch-
AND
seagatest500lt015Match-
VendorProductVersionCPE
seagatest500lt015_firmware-cpe:2.3:o:seagate:st500lt015_firmware:-:*:*:*:*:*:*:*
seagatest500lt015-cpe:2.3:h:seagate:st500lt015:-:*:*:*:*:*:*:*

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

4.2

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

4.5

Confidence

High

EPSS

0.001

Percentile

30.3%

Related for CVE-2015-7269