Security Center

Security Center

Solidigm values your data’s security with a comprehensive SSD vulnerability handling process. Learn about our mitigation for vulnerabilities and create a case here.

Security

Vulnerabilities

Security Advisory

 

Solidigm provides public notification of security vulnerabilities through publication of a Public Security Advisory, document in PDF format posted on Solidigm.com. Each listed security vulnerability is given a CVE-ID (Common Vulnerabilities and Exposures - Identification) and a score based on the CVSS (Common Vulnerability Scoring System)™. Refer to the table below for the Public Security Advisories (PSA), which provides information on the latest FW that has mitigated the vulnerability. Solidigm recommends customers always use the latest available firmware. 
Security Advisory

Public Security Advisory DocumentDate of Publication
Revision 1.1June 2022
Revision 1.1June 2022

Solidigm Product Security Center

To report a Vulnerability

 

If you have information about a security vulnerability or issue with a Solidigm product, please send an email to Security@solidigm.com.

 

  1. If possible, please provide the following information:
  2. Details of the impacted Solidigm product
  3. Description of the issue or vulnerability
  4. Any information regarding known exploitation
  5. Contact information

Solidigm’s Vulnerability Handling Policies

  • Solidigm’s Security Team proactively engages with our customers and industry regarding security vulnerabilities
  • Solidigm follows best known practices to ensure vulnerabilities impacting Solidigm products are documented and communicated in a responsible manner
  • Solidigm is committed to addressing security vulnerabilities in a timely manner, including providing guidance on the impact, severity, and mitigation
  • Vulnerability information is treated in a sensitive manner. Solidigm recommends holding all information in confidence until we can be in contact and respond appropriately.

Solidigm’s Vulnerability Handling Policies

Solidigm’s Security Team follows a defined 4 step process:

01


Vulnerability Reporting 

This is the start of the process where Solidigm becomes aware of a potential security vulnerability. In the case where the potential security has been notified by an external party, Solidigm will acknowledge receipt and will include the party in appropriate Security Disclosure information.

02


This is the start 

This is the start of the process where Solidigm becomes aware of a potential security vulnerability. In the case where the potential security has been notified by an external party, Solidigm will acknowledge receipt and will include the party in appropriate Security Disclosure information.

03


Vulnerability Reporting 

This is the start of the process where Solidigm becomes aware of a potential security vulnerability. In the case where the potential security has been notified by an external party, Solidigm will acknowledge receipt and will include the party in appropriate Security Disclosure information.

04


This is the start 

This is the start of the process where Solidigm becomes aware of a potential security vulnerability. In the case where the potential security has been notified by an external party, Solidigm will acknowledge receipt and will include the party in appropriate Security Disclosure information.