CVE-2026-84696
9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Summary
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Phison Electronics Corporation | PS3111-S11 Controller Firmware | SBFQT1.3 | affected |
Weaknesses
- CWE-306: Missing Authentication for Critical Function
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: total
References
- https://trulycrisp.github.io/drivefirmware/phison_s11/
- https://github.com/trulycrisp/psychite
- https://github.com/trulycrisp/disksec
- https://www.vulncheck.com/advisories/phison-ps3111-s11-controller-firmware-missing-authentication-on-vendor-unique-commands
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.