CVE-2017-18305
Summary
| CVE | CVE-2017-18305 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-23 13:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | XBL sec mem dump system call allows complete control of EL3 by unlocking all XPUs if enable fuse is not blown in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Qualcomm | Mdm9206 | - | All | All | All |
| Hardware | Qualcomm | Mdm9206 | - | All | All | All |
| Operating System | Qualcomm | Mdm9206 Firmware | - | All | All | All |
| Operating System | Qualcomm | Mdm9206 Firmware | - | All | All | All |
| Hardware | Qualcomm | Mdm9607 | - | All | All | All |
| Hardware | Qualcomm | Mdm9607 | - | All | All | All |
| Operating System | Qualcomm | Mdm9607 Firmware | - | All | All | All |
| Operating System | Qualcomm | Mdm9607 Firmware | - | All | All | All |
| Hardware | Qualcomm | Mdm9650 | - | All | All | All |
| Hardware | Qualcomm | Mdm9650 | - | All | All | All |
| Operating System | Qualcomm | Mdm9650 Firmware | - | All | All | All |
| Operating System | Qualcomm | Mdm9650 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 205 | - | All | All | All |
| Hardware | Qualcomm | Sd 205 | - | All | All | All |
| Operating System | Qualcomm | Sd 205 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 205 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 210 | - | All | All | All |
| Hardware | Qualcomm | Sd 210 | - | All | All | All |
| Operating System | Qualcomm | Sd 210 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 210 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 212 | - | All | All | All |
| Hardware | Qualcomm | Sd 212 | - | All | All | All |
| Operating System | Qualcomm | Sd 212 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 212 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 835 | - | All | All | All |
| Hardware | Qualcomm | Sd 835 | - | All | All | All |
| Operating System | Qualcomm | Sd 835 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 835 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Android Security Bulletin—August 2018 | Android Open Source Project | CONFIRM | source.android.com | Third Party Advisory |
| Google Android Multiple Flaws Let Remote Users Execute Arbitrary Code and Let Applications Gain Elevated Privileges and Obtain Potentially Sensitive Information - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Bulletins | Qualcomm | CONFIRM | www.qualcomm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.