ZeroHour

CVE-2017-18124

CVSS 3.0
7.8 high
EPSS
<1%p12
Published
()
Modified
Description

During secure boot, addition is performed on uint8 ptrs which led to overflow issue in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version FSM9055, IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDX20

Vendors
qualcomm
Products
fsm9055 firmware, ipq4019 firmware, mdm9206 firmware, mdm9607 firmware, mdm9625 firmware, mdm9635m firmware, mdm9640 firmware, mdm9645 firmware, mdm9650 firmware, mdm9655 firmware, msm8909w firmware, msm8996au firmware
Weakness
CWE-119
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.