CVE-2026-84696
massMissing authentication for ATA vendor commands in Phison PS3111-S11 SSD firmware
Phison PS3111-S11 SSD controller firmware through version SBFQT1.3 exposes privileged ATA vendor-unique commands (VUCs) with no effective authentication (CWE-306), making the controller's unlock mechanism weak or absent. An attacker with local access and high host privileges (CVSS 4.0: AV:L/PR:H) can bypass the CRC-16-based unlock handshake, or exploit builds shipped without any VUC lock. Once inside, the attacker can read and write controller memory and raw flash, enabling implants that persist across power cycles and potentially tampering with data on the drive. Any system using a SATA SSD built on the PS3111-S11 controller with affected firmware is exposed, though the local attack vector means remote exploitation is not indicated. No public proof-of-concept, no CISA KEV listing, and EPSS of 0.1% indicate no known exploitation to date.
What to do: Determine whether your SSDs use the PS3111-S11 controller and check the firmware version via vendor utilities or smartctl; no fixed firmware version is specified in the available data, so watch for firmware updates from your drive vendor/OEM and apply them when released. Because exploitation requires local access with high privileges, limit privileged local access to hosts with affected drives, and treat persistent-flash implants as a possible cause of anomalies that survive reboots or drive re-imaging.
| Phison PS3111-S11 (S11) SSD controller firmware | through SBFQT1.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.
- Weakness
- CWE-306
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.