SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-18293

When a particular GPIO is protected by blocking access to the corresponding GPIO resource registers, the protection can be bypassed using the corresponding banked GPIO registers instead in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607,…

HIGH 7.8EPSS 0.26%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

When a particular GPIO is protected by blocking access to the corresponding GPIO resource registers, the protection can be bypassed using the corresponding banked GPIO registers instead in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 835, SDA660.

CVSS 3.0
7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.26% probability · 18th percentile
CISA KEV
Not listed
Affected
qualcomm/mdm9206 firmware · qualcomm/mdm9607 firmware · qualcomm/mdm9650 firmware · qualcomm/sd 210 firmware · qualcomm/sd 212 firmware · qualcomm/sd 205 firmware · qualcomm/sd 425 firmware · qualcomm/sd 430 firmware · qualcomm/sd 450 firmware · qualcomm/sd 625 firmware · qualcomm/sd 650 firmware · qualcomm/sd 652 firmware · qualcomm/sd 835 firmware · qualcomm/sda660 firmware
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.