CyberRota Analysis
AI-GeneratedFirmware versions of the Phison PS3111-S11 controller are vulnerable due to the exposure of privileged vendor unique commands over the ATA interface, lacking adequate authentication. This flaw allows attackers to bypass the weak CRC-16 unlock handshake, enabling them to read and write controller memory and raw flash, which could lead to persistent implants. Organizations using affected firmware should prioritize remediation to protect against potential exploitation and data compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.