群联(Phison)PS3111-S11 控制器的固件在验证 RSA 签名时,使用的是嵌入在固件镜像内部的公钥模数(public modulus),而非将其锚定在不可变存储区中。攻击者可以生成任意的 RSA 密钥对,使用私钥对修改后的固件进行签名,并将对应的公钥模数嵌入到签名段中;控制器随后会将这个被篡改的固件视为有效。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Phison Electronics Corporation | PS3111-S11 Controller Firmware | SBFQT1.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Phison Electronics Corporation | PS3111-S11 Controller Firmware | SBFQT1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet