CVE-2017-13218
Access to CNTVCT_EL0 in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear could be used for side channel attacks and this could lead to local information disclosure with no additional execution privileges needed in FSM9055,…
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
Access to CNTVCT_EL0 in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear could be used for side channel attacks and this could lead to local information disclosure with no additional execution privileges needed in FSM9055, IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8909W, QCA4531, QCA9980, QCN5502, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845.
- CVSS 3.0
- 4.7 MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.24% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- google/android
- Source
- security@android.com
References
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.securityfocus.com/bid/102390Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040106Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2018-01-01Vendor Advisory
- https://www.codeaurora.org/security-bulletin/2018/06/04/june-2018-code-aurora-security-bulletin
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.securityfocus.com/bid/102390Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040106Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2018-01-01Vendor Advisory
- https://www.codeaurora.org/security-bulletin/2018/06/04/june-2018-code-aurora-security-bulletin
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.