2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2017-18302" ,
"sourceIdentifier" : "product-security@qualcomm.com" ,
"published" : "2018-09-20T13:29:00.510" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T03:19:48.723" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016, a crafted HLOS client can modify the structure in memory passed to a QSEE application between the time of check and the time of use, resulting in arbitrary writes to TZ kernel memory regions."
} ,
{
"lang" : "es" ,
"value" : "En Snapdragon (Automobile y Mobile) en versiones MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660 y Snapdragon_High_Med_2016, un cliente HLOS manipulado puede modificar la estructura en la memoria pasada a una aplicaci\u00f3n QSEE entre el momento de la comprobaci\u00f3n y el momento del uso, lo que desemboca en escrituras arbitrarias a las regiones de memoria del kernel TZ."
}
] ,
"metrics" : {
"cvssMetricV30" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.0" ,
"vectorString" : "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 4.7 ,
"baseSeverity" : "MEDIUM" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "LOCAL" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 1.0 ,
"impactScore" : 3.6
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:L/AC:M/Au:N/C:N/I:C/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 4.7 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "LOCAL" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "COMPLETE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 3.4 ,
"impactScore" : 6.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-362"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:msm8996au_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8CA1E7B0-782B-4757-B118-802943798984"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:msm8996au:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "95CB08EC-AE12-4A54-AA3C-998F01FC8763"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sd425_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BC5ECC0E-0120-47E5-9D00-440DC38F2C0B"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sd425:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "352E745F-375B-43AE-9B29-8A2D50C695B4"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sd427_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C9CDD792-89BC-4A7B-A971-4C04663E62A7"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sd427:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "64D6ACA2-47C7-4E44-A838-22600B5BC52E"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sd430_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F6652C54-B207-4816-B70D-5DD2C792D1DF"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sd430:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FD3B99CC-CC53-42A6-9C42-0C06E734A554"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sd435_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7C2951AF-E04B-433B-B327-03D8D28B2BDE"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sd435:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "084BB475-8F09-408E-AF1C-D0CA4DD8D414"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sd450_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BF6EA9F3-ED14-4DAC-93D1-2DF63C7C3EAC"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sd450:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C4EF0B75-2431-4E44-B515-11C9BD4BC982"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sd625_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7C5E72A3-2117-4190-978F-EFB4DDE4EC9F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sd625:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AD2EEF23-73EB-49AE-B9F1-4702D545D643"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sd650_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3A83A1CF-396D-403F-AA22-0ED817DD384B"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sd650:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "21AEAA09-3C1B-4413-8418-63644DB3FABA"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sd652_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E6C536B0-32E9-42D0-B298-B4D77CC94914"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sd652:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8F81E096-820A-4B27-A539-5D3BA39FA5C9"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sd820_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BC508C49-0B76-43A8-B2AF-0F8EB989E238"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sd820:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E9665200-D306-4EEB-9F42-6C5963524179"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sd820a_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CB757118-0F90-4E6E-AD4F-A05A5791B20C"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sd820a:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2BCD9420-26A7-4444-9AA4-D7B0AC42FA84"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sd835_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9DA605FD-B801-43BB-B52D-879013F7F57E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sd835:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "908BFD96-0423-4AFC-B8F3-105B2D5B4C73"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sda660_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A2326BD7-28A5-4244-8501-B109913E7AE6"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sda660:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "532D244B-8B5A-4923-B7F1-9DC0A5FC0E9D"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sdm429_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9DFD2C9A-6C25-4B8F-BE64-DAD3DCCDEADD"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sdm429:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8DE61FCE-CA87-46E1-981D-B44697E54CB1"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sdm439_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "84289E6D-DA2A-4D04-9DDA-E8C46DDDD056"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sdm439:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C0B56360-7AC3-410A-B7F8-1BE8514B3781"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sdm630_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8EA0D645-80F6-48C3-AF0D-99198ADC8778"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sdm630:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "814FF3F3-CD5A-45A3-988C-6457D2CEB48C"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sdm632_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A02E12AC-F845-4164-9D95-ACD7167B6DD6"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sdm632:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "321F7DE7-E6E9-449F-867B-04A9F53334B0"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sdm636_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8F00D854-0AC7-415F-B19A-642CB9F72210"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sdm636:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F977B432-2709-4D75-AA3E-F440285B7BA2"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sdm660_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "24D7B67C-6FEC-48F8-9D46-778E4528BC20"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sdm660:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "05006807-D961-446C-B8DC-C87507F1316E"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://www.securitytracker.com/id/1041432" ,
"source" : "product-security@qualcomm.com" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-components" ,
"source" : "product-security@qualcomm.com" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "https://www.qualcomm.com/company/product-security/bulletins" ,
"source" : "product-security@qualcomm.com" ,
"tags" : [
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "http://www.securitytracker.com/id/1041432" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-components" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "https://www.qualcomm.com/company/product-security/bulletins" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}