Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-10637


Marvell SSD Controller (88SS1074, 88SS1079, 88SS1080, 88SS1093, 88SS1092, 88SS1095, 88SS9174, 88SS9175, 88SS9187, 88SS9188, 88SS9189, 88SS9190, 88SS1085, 88SS1087, 88SS1090, 88SS1100, 88SS1084, 88SS1088, & 88SS1098) devices are vulnerable in manipulating a combination of IO pins to bypass the secure boot protection mechanism.


Security Impact Summary

This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 4.6, with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts integrity (unauthorized modifications), for affected systems. Impacting 38 products from marvell, from marvell, from marvell and 35 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

First disclosed in 2019, this vulnerability was reported during a period defined by widespread IoT adoption challenges, mobile security concerns, and the emergence of advanced persistent threat (APT) techniques. Contemporary mitigation strategies focused on secure development practices and third-party component vetting.


Published

2019-06-05T16:29:00.243

Last Modified

2024-11-21T04:19:38.470

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 4.6 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System marvell 88ss1074_firmware - Yes
Hardware marvell 88ss1074 - No
Operating System marvell 88ss1079_firmware - Yes
Hardware marvell 88ss1079 - No
Operating System marvell 88ss1080_firmware - Yes
Hardware marvell 88ss1080 - No
Operating System marvell 88ss1093_firmware - Yes
Hardware marvell 88ss1093 - No
Operating System marvell 88ss1092_firmware - Yes
Hardware marvell 88ss1092 - No
Operating System marvell 88ss1095_firmware - Yes
Hardware marvell 88ss1095 - No
Operating System marvell 88ss9174_firmware - Yes
Hardware marvell 88ss9174 - No
Operating System marvell 88ss9175_firmware - Yes
Hardware marvell 88ss9175 - No
Operating System marvell 88ss9187_firmware - Yes
Hardware marvell 88ss9187 - No
Operating System marvell 88ss9188_firmware - Yes
Hardware marvell 88ss9188 - No
Operating System marvell 88ss9189_firmware - Yes
Hardware marvell 88ss9189 - No
Operating System marvell 88ss9190_firmware - Yes
Hardware marvell 88ss9190 - No
Operating System marvell 88ss1085_firmware - Yes
Hardware marvell 88ss1085 - No
Operating System marvell 88ss1087_firmware - Yes
Hardware marvell 88ss1087 - No
Operating System marvell 88ss1090_firmware - Yes
Hardware marvell 88ss1090 - No
Operating System marvell 88ss1100_firmware - Yes
Hardware marvell 88ss1100 - No
Operating System marvell 88ss1084_firmware - Yes
Hardware marvell 88ss1084 - No
Operating System marvell 88ss1088_firmware - Yes
Hardware marvell 88ss1088 - No
Operating System marvell 88ss1098_firmware - Yes
Hardware marvell 88ss1098 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For marvell's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.