First published: Mon Sep 30 2019(Updated: )
Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the applications download resources from the Dashboard web service. This vulnerability may allow an attacker to substitute downloaded resources with arbitrary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SanDisk SSD Dashboard | <2.5.1.0 | |
Westerndigital Ssd Dashboard | <2.5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13467 is a vulnerability in the Western Digital SSD Dashboard and SanDisk SSD Dashboard applications that could allow man-in-the-middle attacks.
The severity of CVE-2019-13467 is medium with a CVSS score of 5.9.
Western Digital SSD Dashboard before version 2.5.1.0 and SanDisk SSD Dashboard before version 2.5.1.0 are potentially vulnerable to this CVE-2019-13467.
An attacker could exploit CVE-2019-13467 by performing man-in-the-middle attacks when the affected applications download resources from the Dashboard web service.
You can find more information about CVE-2019-13467 at the following references: - [Western Digital Support](https://support.wdc.com/downloads.aspx?g=907&lang=en) - [Western Digital Product Security](https://www.westerndigital.com/support/productsecurity/wdc-19009-sandisk-and-western-digital-ssd-dashboard-vulnerabilities)