ZeroHour

CVE-2017-18313

CVSS 3.0
5.3 medium
EPSS
<1%p17
Published
()
Modified
Description

Under certain mode of operations, HLOS may be able get direct or indirect access through DXE channels to tamper with the authenticated WCNSS firmware stored in DDR because DXE-accessible memory is located within the authenticated image in Snapdragon Mobile and Snapdragon Wear in version MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD 617.

Vendors
qualcomm
Products
msm8909w firmware, sd 210 firmware, sd 212 firmware, sd 205 firmware, sd 410 firmware, sd 412 firmware, sd 615 firmware, sd 616 firmware, sd 415 firmware, sd 617 firmware
Vector
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.