PT-2018-6831 · Qualcomm · Snapdragon Wear+1

Published

2018-10-23

·

Updated

2019-10-03

·

CVE-2017-18313

CVSS v2.0

5.7

Medium

VectorAV:A/AC:M/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions: Qualcomm Snapdragon Mobile and Snapdragon Wear versions MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD 617
Description: The issue allows HLOS to potentially access and tamper with authenticated WCNSS firmware stored in DDR through DXE channels under certain conditions. This is because DXE-accessible memory is located within the authenticated image.
Recommendations: For Qualcomm Snapdragon Mobile and Snapdragon Wear versions MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD 617, consider restricting access to DXE channels as a temporary workaround until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-18313

Affected Products

Snapdragon Mobile
Snapdragon Wear