CVE-2017-18305
XBL sec mem dump system call allows complete control of EL3 by unlocking all XPUs if enable fuse is not blown in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835.
Published:Oct 23, 2018
Last Modified:Nov 21, 2024
EPS:Oct 23, 2018
EPSS Score:0.00053
CVSS Score:7
Affected Products
Vendor
Product
Action
Vendor
Qualcomm
Product
Mdm9206
Qualcomm
Mdm9206
Vendor
Qualcomm
Product
Mdm9206 Firmware
Qualcomm
Mdm9206 Firmware
Vendor
Qualcomm
Product
Mdm9607
Qualcomm
Mdm9607
Vendor
Qualcomm
Product
Mdm9607 Firmware
Qualcomm
Mdm9607 Firmware
Vendor
Qualcomm
Product
Mdm9650
Qualcomm
Mdm9650
Vendor
Qualcomm
Product
Mdm9650 Firmware
Qualcomm
Mdm9650 Firmware
Vendor
Qualcomm
Product
Sd 205
Qualcomm
Sd 205
Vendor
Qualcomm
Product
Sd 205 Firmware
Qualcomm
Sd 205 Firmware
Vendor
Qualcomm
Product
Sd 210
Qualcomm
Sd 210
Vendor
Qualcomm
Product
Sd 210 Firmware
Qualcomm
Sd 210 Firmware
Vendor
Qualcomm
Product
Sd 212
Qualcomm
Sd 212
Vendor
Qualcomm
Product
Sd 212 Firmware
Qualcomm
Sd 212 Firmware
Vendor
Qualcomm
Product
Sd 835
Qualcomm
Sd 835
Vendor
Qualcomm
Product
Sd 835 Firmware
Qualcomm
Sd 835 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
