ZeroHour

CVE-2017-18292

CVSS 3.0
5.5 medium
EPSS
<1%p16
Published
()
Modified
Description

Secure app running in non secure space can restart TZ by calling Widevine app API repeatedly in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 820A.

Vendors
qualcomm
Products
msm8909w firmware, msm8996au firmware, sd 210 firmware, sd 212 firmware, sd 205 firmware, sd 410 firmware, sd 412 firmware, sd 425 firmware, sd 430 firmware, sd 450 firmware, sd 615 firmware, sd 616 firmware
Weakness
CWE-20
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.