CVE-2017-18313

MEDIUM

Snapdragon <MSM8909W-SD 617 - Info Disclosure

Title source: llm
STIX 2.1

Description

Under certain mode of operations, HLOS may be able get direct or indirect access through DXE channels to tamper with the authenticated WCNSS firmware stored in DDR because DXE-accessible memory is located within the authenticated image in Snapdragon Mobile and Snapdragon Wear in version MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD 617.

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0015
EPSS Percentile 35.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

Status published
Products (10)
qualcomm/msm8909w_firmware
qualcomm/sd_205_firmware
qualcomm/sd_210_firmware
qualcomm/sd_212_firmware
qualcomm/sd_410_firmware
qualcomm/sd_412_firmware
qualcomm/sd_415_firmware
qualcomm/sd_615_firmware
qualcomm/sd_616_firmware
qualcomm/sd_617_firmware
Published Oct 23, 2018
Tracked Since Feb 18, 2026