ZeroHour

CVE-2017-18280

CVSS 3.0
7.8 high
EPSS
<1%p16
Published
()
Modified
Description

In Snapdragon (Automobile, Mobile, Wear) in version MDM9607, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDM429, SDM439, SDM632, Snapdragon_High_Med_2016, when a Trusted Application has opened the SPI/I2C interface to a particular device, it is possible for another Trusted Application to read the data on this open interface by calling the SPI/I2C read function.

Vendors
qualcomm
Products
mdm9607 firmware, msm8909w firmware, msm8996au firmware, sd210 firmware, sd212 firmware, sd205 firmware, sd425 firmware, sd427 firmware, sd430 firmware, sd435 firmware, sd450 firmware, sd617 firmware
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.