CVE-2017-18292 Information

Description

Secure app running in non secure space can restart TZ by calling Widevine app API repeatedly in Snapdragon Automobile Snapdragon Mobile and Snapdragon Wear in versions MSM8909W MSM8996AU SD 210/SD 212/SD 205 SD 410/12 SD 425 SD 430 SD 450 SD 615/16/SD 415 SD 617 SD 625 SD 650/52 SD 800 SD 810 SD 820 SD 820A.

CVSS Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Reference

http://www.securitytracker.com/id/1041432 https://source.android.com/security/bulletin/2018-08-01qualcomm-closed-source-components https://www.qualcomm.com/company/product-security/bulletins

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

5.5

Share on: