CVE-2017-18282
Last modified
CVE-2017-18282 is a vulnerability of currently unknown severity. Non-secure SW can cause SDCC to generate secure bus accesses, which may expose RPM access in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 835, SDA660.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Non-secure SW can cause SDCC to generate secure bus accesses, which may expose RPM access in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 835, SDA660.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Mdm9206 Firmware | All versions |
| Qualcomm | Mdm9607 Firmware | All versions |
| Qualcomm | Mdm9650 Firmware | All versions |
| Qualcomm | Sd210 Firmware | All versions |
| Qualcomm | Sd212 Firmware | All versions |
| Qualcomm | Sd205 Firmware | All versions |
| Qualcomm | Sd425 Firmware | All versions |
| Qualcomm | Sd430 Firmware | All versions |
| Qualcomm | Sd450 Firmware | All versions |
| Qualcomm | Sd625 Firmware | All versions |
| Qualcomm | Sd650 Firmware | All versions |
| Qualcomm | Sd652 Firmware | All versions |
| Qualcomm | Sd835 Firmware | All versions |
| Qualcomm | Sda660 Firmware | All versions |
References
- http://www.securitytracker.com/id/1041432Third Party Advisory, VDB Entry
- https://www.qualcomm.com/company/product-security/bulletinsVendor Advisory
- http://www.securitytracker.com/id/1041432Third Party Advisory, VDB Entry
- https://www.qualcomm.com/company/product-security/bulletinsVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-18282?
How severe is CVE-2017-18282?
How do I fix CVE-2017-18282?
Are you affected by CVE-2017-18282?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
