CVE-2015-9137: High severity android vulnerability
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, SD 845, SD 850, and SDX20, several EFS2 DIAG command handlers are not calling fsdiagaccesscheck().
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2015-9137.
What is the severity level of CVE-2015-9137?
The severity level of CVE-2015-9137 is high with a CVSS score of 7.5.
Which products are affected by CVE-2015-9137?
CVE-2015-9137 affects Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 617.
How can I fix CVE-2015-9137?
To fix CVE-2015-9137, update your Android device to a version that includes the security patch released on or after April 5, 2018.
Where can I find more information about CVE-2015-9137?
You can find more information about CVE-2015-9137 on the following websites: [SecurityFocus](http://www.securityfocus.com/bid/103671), [Android Security Bulletin - April 2018](https://source.android.com/security/bulletin/2018-04-01), [Android Security Bulletin - April 2018 - Asterisk](https://source.android.com/docs/security/bulletin/2018-04-01/#asterisk).