CVE-2026-84696
Received Received - Intake

Phison PS3111-S11 Firmware Privileged Command Bypass

Vulnerability report for CVE-2026-84696, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: VulnCheck

Description

Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
phison ps3111-s11_controller_firmware to SBFQT1.3 (inc)
phison ps3111-s11 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Phison PS3111-S11 controller firmware through version SBFQT1.3. It involves missing or weak authentication on vendor unique commands (VUCs) exposed over the ATA interface. Attackers can bypass a weak CRC-16 unlock handshake or use builds without VUC locks to read and write controller memory and raw flash storage. This allows persistent malware implants that survive power cycles.

Detection Guidance

Use DiskSec to check for unauthorized access to Vendor Unique Commands (VUCs) on storage drives. Run it with root/admin privileges to list drives and test for weak authentication on firmware commands. Check for unexpected firmware modifications or memory access patterns.

Impact Analysis

An attacker with local access could exploit this to read or write firmware, install persistent malware, or access sensitive data stored on the drive. This could lead to data theft, system compromise, or complete control over the affected storage device, even after reboot.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance failures due to inadequate protection of personal or health information stored on affected drives, potentially resulting in legal penalties or data breach notifications.

Mitigation Strategies

Disable or restrict physical access to systems using Phison PS3111-S11 controllers. Update firmware to versions beyond SBFQT1.3 if available. Monitor for unauthorized VUC usage or firmware changes. Consider replacing affected drives if updates are not feasible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84696. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart