CVE-2017-18160
CRITICALQualcomm Mdm9635m Firmware - Cryptographic Issue
Title source: ruleDescription
AGPS session failure in GNSS module due to cyphersuites are hardcoded and needed manual update everytime in snapdragon mobile and snapdragon wear in versions MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 835, SD 845, SD 850
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://www.qualcomm.com/company/product-security/bulletins
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/106128
Scores
CVSS v3
9.8
EPSS
0.0022
EPSS Percentile
44.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-310
Status
published
Products (8)
qualcomm/mdm9635m_firmware
qualcomm/mdm9645_firmware
qualcomm/mdm9650_firmware
qualcomm/mdm9655_firmware
qualcomm/msm8909w_firmware
qualcomm/sd_835_firmware
qualcomm/sd_845_firmware
qualcomm/sd_850_firmware
Published
Jan 18, 2019
Tracked Since
Feb 18, 2026