Vulnerabilities > CVE-2015-7269 - 7PK - Security Features vulnerability in Seagate St500Lt015 Firmware

047910
CVSS 4.2 - MEDIUM
Attack vector
PHYSICAL
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
high complexity
seagate
CWE-254

Summary

Seagate ST500LT015 hard disk drives, when operating in eDrive mode on Lenovo ThinkPad W541 laptops with BIOS 2.21, allow physically proximate attackers to bypass self-encrypting drive (SED) protection by attaching a second SATA connector to exposed pins, maintaining an alternate power source, and attaching the data cable to another machine, aka a "Hot Unplug Attack."

Vulnerable Configurations

Part Description Count
OS
Seagate
1
Hardware
Seagate
1

Common Weakness Enumeration (CWE)