CVE-2019-13466: Sandisk Ssd Dashboard

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The “generate reports” archive is protected with a hard-coded password. An application update that addresses the protection of archive encryption is available.

Affected products

  • Sandisk Ssd Dashboard: before 2.5.1.0 (fixed in 2.5.1.0)
  • Westerndigital Ssd Dashboard: before 2.5.1.0 (fixed in 2.5.1.0)

Published 2019-09-30. Last modified 2026-06-17.