设计工具
公司

微米 statement on potential industry vulnerability in optional ATA interface command

微米 Technology | January 2022

We are aware that a paper recently published via IEEE Xplore titled, “Forensic Issues and Techniques to Improve 安全 in 固态硬盘 With Flex Capacity Feature,” has raised security questions about the variable over-provisioning capability in industry devices that use the ATA standard set max address command, including the 微米 5200 固态硬盘. 微米 takes data security very seriously, and we strive to design with exacting security standards. We welcome re搜索 in this field and value collaborations that will improve the security of our products. Any time a potential security concern for one of our products is brought to our attention, 微米 conducts a detailed investigation to assess whether our products might be susceptible to such a vulnerability.

Our thorough analysis determined that there is no vulnerability in our products that could be exploited as described in the referenced paper.

During our investigation we did identify a related potential vulnerability that is theoretically possible in two of our product lines, the 微米 5200 and 5300 data center SATA 固态硬盘s. In order to exploit this potential vulnerability, the attacker would have to have privileged authorization to issue special commands to the drive, and therefore it is unlikely to be exposed to users in a virtualized cloud infrastructure or enterprise data center. 尽管如此, 微米 will be issuing an optional firmware update that will address this potential vulnerability to any customer who is concerned about this issue for the affected products.

Please contact your 微米 sales representative with any questions.