CVE-2017-18312

HIGH

Qualcomm Msm8996au Firmware - Missing Authorization

Title source: rule
STIX 2.1

Description

While accessing SafeSwitch services, third party can manipulate a given device and perform unauthorized operation due to lack of checking of same state transitions in Snapdragon Automobile, Snapdragon Mobile in version MSM8996AU, SD 410/12, SD 617, SD 650/52, SD 810, SD 820, SD 820A

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0008
EPSS Percentile 23.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-862
Status published
Products (9)
qualcomm/msm8996au_firmware
qualcomm/sd_410_firmware
qualcomm/sd_412_firmware
qualcomm/sd_617_firmware
qualcomm/sd_650_firmware
qualcomm/sd_652_firmware
qualcomm/sd_810_firmware
qualcomm/sd_820_firmware
qualcomm/sd_820a_firmware
Published Oct 23, 2018
Tracked Since Feb 18, 2026