ZeroHour

CVE-2018-11259

CVSS 3.0
7.7 high
EPSS
<1%p10
Published
()
Modified
Description

Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based device, the EFS partition can be erased. Apps processor then has non-secure world full read/write access to the partition until the modem boots and configures the EFS partition addresses in its MPU partition.

Vendors
qualcomm
Products
mdm9206 firmware, mdm9607 firmware, mdm9635m firmware, mdm9640 firmware, mdm9650 firmware, mdm9655 firmware, msm8909w firmware, msm8996au firmware, sd 210 firmware, sd 212 firmware, sd 205 firmware, sd 410 firmware
Weakness
CWE-732
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.