ZeroHour

CVE-2026-84696

mass

Missing authentication for ATA vendor commands in Phison PS3111-S11 SSD firmware

CVSS 4.0
9.3 critical
EPSS
<1%p4
Published
()
Modified
AI analysis

Phison PS3111-S11 SSD controller firmware through version SBFQT1.3 exposes privileged ATA vendor-unique commands (VUCs) with no effective authentication (CWE-306), making the controller's unlock mechanism weak or absent. An attacker with local access and high host privileges (CVSS 4.0: AV:L/PR:H) can bypass the CRC-16-based unlock handshake, or exploit builds shipped without any VUC lock. Once inside, the attacker can read and write controller memory and raw flash, enabling implants that persist across power cycles and potentially tampering with data on the drive. Any system using a SATA SSD built on the PS3111-S11 controller with affected firmware is exposed, though the local attack vector means remote exploitation is not indicated. No public proof-of-concept, no CISA KEV listing, and EPSS of 0.1% indicate no known exploitation to date.

What to do: Determine whether your SSDs use the PS3111-S11 controller and check the firmware version via vendor utilities or smartctl; no fixed firmware version is specified in the available data, so watch for firmware updates from your drive vendor/OEM and apply them when released. Because exploitation requires local access with high privileges, limit privileged local access to hosts with affected drives, and treat persistent-flash implants as a possible cause of anomalies that survive reboots or drive re-imaging.

Affected
Phison PS3111-S11 (S11) SSD controller firmwarethrough SBFQT1.3
Estimated exposure
masslikely tens of millions of drives (S11-series controllers have shipped broadly in consumer and OEM SATA SSDs) — Phison is one of the highest-volume SSD controller suppliers and the PS3111-S11 is used across numerous retail and OEM SATA SSD models, so the installed base of potentially affected drives plausibly runs into the tens of millions, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.

Weakness
CWE-306
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.