ZeroHour

CVE-2017-14911

CVSS 3.0
9.8 critical
EPSS
2%p82
Published
()
Modified
Description

In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile, Snapdragon Automobile APQ8096AU, MDM9206, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 625, SD 650/52, SD 820, SD 835, it is possible for the XBL loader to skip the authentication of device config.

Vendors
qualcomm
Products
mdm9206 firmware, apq8096au firmware, msm8996au firmware, mdm9650 firmware, sd 210 firmware, sd 212 firmware, sd 205 firmware, sd 425 firmware, sd 430 firmware, sd 625 firmware, sd 650 firmware, sd 652 firmware
Weakness
CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.