If a remote hacker or a malware gains full root/admin rights on a system, is there any way to access another SATA disk that has been hardware connected but disabled in BIOS ?
I am not sure if the disabled disk even has power in that case (I guess it has not) but I found the following post which raised some doubts : https://superuser.com/a/111009
OS considered : Windows or Linux
Threat Model : Physical access and BIOS reflash are out of scope as it is game over anyway in such cases.
Except this, consider full control of compromised disk system: hacker can issue any command, can modify MBR, kernel, flash the compromised disk firmware, ...