CVE-2017-18292
—CVSS 3.0
5.5 medium
EPSS
<1%p16
Published
()
Modified
Description
Secure app running in non secure space can restart TZ by calling Widevine app API repeatedly in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 820A.
- Vendors
- qualcomm
- Products
- msm8909w firmware, msm8996au firmware, sd 210 firmware, sd 212 firmware, sd 205 firmware, sd 410 firmware, sd 412 firmware, sd 425 firmware, sd 430 firmware, sd 450 firmware, sd 615 firmware, sd 616 firmware
- Weakness
- CWE-20
- Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.