PT-2018-6824 · Qualcomm · Snapdragon Wear+1
Published
2018-10-23
·
Updated
2019-10-03
·
CVE-2017-18305
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Snapdragon Mobile versions MDM9206, MDM9607, MDM9650
Snapdragon Wear versions MDM9206, MDM9607, MDM9650
Snapdragon Mobile versions SD 210, SD 212, SD 205
Snapdragon Mobile versions SD 835
Description:
The issue allows for complete control of EL3 by unlocking all XPUs if the enable fuse is not blown, potentially leading to a security breach. This is related to the XBL sec mem dump system call in Snapdragon Mobile and Snapdragon Wear.
Recommendations:
For Snapdragon Mobile version MDM9206, ensure the enable fuse is blown to prevent exploitation.
For Snapdragon Mobile version MDM9607, ensure the enable fuse is blown to prevent exploitation.
For Snapdragon Mobile version MDM9650, ensure the enable fuse is blown to prevent exploitation.
For Snapdragon Wear version MDM9206, ensure the enable fuse is blown to prevent exploitation.
For Snapdragon Wear version MDM9607, ensure the enable fuse is blown to prevent exploitation.
For Snapdragon Wear version MDM9650, ensure the enable fuse is blown to prevent exploitation.
For Snapdragon Mobile version SD 210, ensure the enable fuse is blown to prevent exploitation.
For Snapdragon Mobile version SD 212, ensure the enable fuse is blown to prevent exploitation.
For Snapdragon Mobile version SD 205, ensure the enable fuse is blown to prevent exploitation.
For Snapdragon Mobile version SD 835, ensure the enable fuse is blown to prevent exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snapdragon Mobile
Snapdragon Wear