CVE-2017-18313
Under certain mode of operations, HLOS may be able get direct or indirect access through DXE channels to tamper with the authenticated WCNSS firmware stored in DDR because DXE-accessible memory is located within the authenticated image in Snapdragon…
Does this matter?
Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.
Description
Under certain mode of operations, HLOS may be able get direct or indirect access through DXE channels to tamper with the authenticated WCNSS firmware stored in DDR because DXE-accessible memory is located within the authenticated image in Snapdragon Mobile and Snapdragon Wear in version MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD 617.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.26% probability · 17th percentile
- CISA KEV
- Not listed
- Affected
- qualcomm/msm8909w firmware · qualcomm/sd 210 firmware · qualcomm/sd 212 firmware · qualcomm/sd 205 firmware · qualcomm/sd 410 firmware · qualcomm/sd 412 firmware · qualcomm/sd 615 firmware · qualcomm/sd 616 firmware · qualcomm/sd 415 firmware · qualcomm/sd 617 firmware
- Source
- product-security@qualcomm.com
References
- https://source.android.com/security/bulletin/2018-09-01#qualcomm-closed-source-componentsThird Party Advisory
- https://www.qualcomm.com/company/product-security/bulletinsVendor Advisory
- https://source.android.com/security/bulletin/2018-09-01#qualcomm-closed-source-componentsThird Party Advisory
- https://www.qualcomm.com/company/product-security/bulletinsVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.