PT-2018-6831 · Qualcomm · Snapdragon Wear+1
Published
2018-10-23
·
Updated
2019-10-03
·
CVE-2017-18313
CVSS v2.0
5.7
Medium
| Vector | AV:A/AC:M/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions:
Qualcomm Snapdragon Mobile and Snapdragon Wear versions MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD 617
Description:
The issue allows HLOS to potentially access and tamper with authenticated WCNSS firmware stored in DDR through DXE channels under certain conditions. This is because DXE-accessible memory is located within the authenticated image.
Recommendations:
For Qualcomm Snapdragon Mobile and Snapdragon Wear versions MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD 617, consider restricting access to DXE channels as a temporary workaround until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snapdragon Mobile
Snapdragon Wear