Vulnerabilidad · Publicado 31/08/2026
El controlador de almacenamiento Phison PS3111-S11 valida firmas RSA utilizando claves públicas embebidas en la imagen del firmware en lugar de almacenamiento inmutable, permitiendo a atacantes generar pares de claves RSA arbitrarios y firmar firmware modificado que el controlador acepta como legítimo. Esta vulnerabilidad afecta directamente a servidores, sistemas de backup y centros de datos en LATAM que utilizan almacenamiento basado en estos controladores, comprometiendo la integridad del firmware de dispositivos de almacenamiento altas.
Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can generate arbitrary RSA key pairs, sign modified firmware with the private key, embed the matching modulus in the signature segment, and the controller accepts the tampered firmware as valid.
Score: 8.2/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-347
Publicado en NIST NVD.