{"api_version":"1","generated_at":"2026-07-23T09:40:15+00:00","cve":"CVE-2017-13238","urls":{"html":"https://cve.report/CVE-2017-13238","api":"https://cve.report/api/cve/CVE-2017-13238.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-13238","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-13238"},"summary":{"title":"CVE-2017-13238","description":"In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-64610940.","state":"PUBLIC","assigner":"security@android.com","published_at":"2018-02-12 19:29:00","updated_at":"2018-03-13 14:44:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://source.android.com/security/bulletin/2018-02-01","name":"https://source.android.com/security/bulletin/2018-02-01","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Android Security Bulletin—February 2018  |  Android Open Source Project","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/103024","name":"103024","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Google Android HTC Components CVE-2017-13238 Local Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-13238","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-13238","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"13238","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"13238","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@android.com","DATE_PUBLIC":"2018-02-05T00:00:00","ID":"CVE-2017-13238","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Android","version":{"version_data":[{"version_value":"Android kernel"}]}}]},"vendor_name":"Google Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-64610940."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Information disclosure"}]}]},"references":{"reference_data":[{"name":"103024","refsource":"BID","url":"http://www.securityfocus.com/bid/103024"},{"name":"https://source.android.com/security/bulletin/2018-02-01","refsource":"CONFIRM","url":"https://source.android.com/security/bulletin/2018-02-01"}]}},"nvd":{"publishedDate":"2018-02-12 19:29:00","lastModifiedDate":"2018-03-13 14:44:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.2,"baseSeverity":"MEDIUM"},"exploitabilityScore":0.5,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:N/A:N","accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.7},"severity":"MEDIUM","exploitabilityScore":3.4,"impactScore":6.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:google:android:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"13238","Ordinal":"110657","Title":"CVE-2017-13238","CVE":"CVE-2017-13238","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"13238","Ordinal":"1","NoteData":"In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-64610940.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"13238","Ordinal":"2","NoteData":"2018-02-12","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"13238","Ordinal":"3","NoteData":"2018-02-16","Type":"Other","Title":"Modified"}]}}}