CVE-2017-18302
In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016, a crafted HLOS client can modify the structure in memory passed to a QSEE application between the time of check and the time of use, resulting in arbitrary writes to TZ kernel memory regions.
Published:Sep 20, 2018
Last Modified:Nov 21, 2024
EPS:Sep 20, 2018
EPSS Score:0.00047
CVSS Score:4.7
Affected Products
Vendor
Product
Action
Vendor
Qualcomm
Product
Msm8996au
Qualcomm
Msm8996au
Vendor
Qualcomm
Product
Msm8996au Firmware
Qualcomm
Msm8996au Firmware
Vendor
Qualcomm
Product
Sd425
Qualcomm
Sd425
Vendor
Qualcomm
Product
Sd425 Firmware
Qualcomm
Sd425 Firmware
Vendor
Qualcomm
Product
Sd427
Qualcomm
Sd427
Vendor
Qualcomm
Product
Sd427 Firmware
Qualcomm
Sd427 Firmware
Vendor
Qualcomm
Product
Sd430
Qualcomm
Sd430
Vendor
Qualcomm
Product
Sd430 Firmware
Qualcomm
Sd430 Firmware
Vendor
Qualcomm
Product
Sd435
Qualcomm
Sd435
Vendor
Qualcomm
Product
Sd435 Firmware
Qualcomm
Sd435 Firmware
Vendor
Qualcomm
Product
Sd450
Qualcomm
Sd450
Vendor
Qualcomm
Product
Sd450 Firmware
Qualcomm
Sd450 Firmware
Vendor
Qualcomm
Product
Sd625
Qualcomm
Sd625
Vendor
Qualcomm
Product
Sd625 Firmware
Qualcomm
Sd625 Firmware
Vendor
Qualcomm
Product
Sd650
Qualcomm
Sd650
Vendor
Qualcomm
Product
Sd650 Firmware
Qualcomm
Sd650 Firmware
Vendor
Qualcomm
Product
Sd652
Qualcomm
Sd652
Vendor
Qualcomm
Product
Sd652 Firmware
Qualcomm
Sd652 Firmware
Vendor
Qualcomm
Product
Sd820
Qualcomm
Sd820
Vendor
Qualcomm
Product
Sd820 Firmware
Qualcomm
Sd820 Firmware
Vendor
Qualcomm
Product
Sd820a
Qualcomm
Sd820a
Vendor
Qualcomm
Product
Sd820a Firmware
Qualcomm
Sd820a Firmware
Vendor
Qualcomm
Product
Sd835
Qualcomm
Sd835
Vendor
Qualcomm
Product
Sd835 Firmware
Qualcomm
Sd835 Firmware
Vendor
Qualcomm
Product
Sda660
Qualcomm
Sda660
Vendor
Qualcomm
Product
Sda660 Firmware
Qualcomm
Sda660 Firmware
Vendor
Qualcomm
Product
Sdm429
Qualcomm
Sdm429
Vendor
Qualcomm
Product
Sdm429 Firmware
Qualcomm
Sdm429 Firmware
Vendor
Qualcomm
Product
Sdm439
Qualcomm
Sdm439
Vendor
Qualcomm
Product
Sdm439 Firmware
Qualcomm
Sdm439 Firmware
Vendor
Qualcomm
Product
Sdm630
Qualcomm
Sdm630
Vendor
Qualcomm
Product
Sdm630 Firmware
Qualcomm
Sdm630 Firmware
Vendor
Qualcomm
Product
Sdm632
Qualcomm
Sdm632
Vendor
Qualcomm
Product
Sdm632 Firmware
Qualcomm
Sdm632 Firmware
Vendor
Qualcomm
Product
Sdm636
Qualcomm
Sdm636
Vendor
Qualcomm
Product
Sdm636 Firmware
Qualcomm
Sdm636 Firmware
Vendor
Qualcomm
Product
Sdm660
Qualcomm
Sdm660
Vendor
Qualcomm
Product
Sdm660 Firmware
Qualcomm
Sdm660 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
