CVE-2017-18305 Information

Description

XBL sec mem dump system call allows complete control of EL3 by unlocking all XPUs if enable fuse is not blown in Snapdragon Mobile Snapdragon Wear in version MDM9206 MDM9607 MDM9650 SD 210/SD 212/SD 205 SD 835.

CVSS Vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

http://www.securitytracker.com/id/1041432 https://source.android.com/security/bulletin/2018-08-01qualcomm-closed-source-components https://www.qualcomm.com/company/product-security/bulletins

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.0

Share on: