CVE-2017-14906: Critical severity android vulnerability
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, PKCS7 padding is not supported by the crypto storage APIs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14906?
CVE-2017-14906 has a high severity rating due to the implications of the unsupported PKCS7 padding in crypto storage APIs.
How do I fix CVE-2017-14906?
To mitigate CVE-2017-14906, update your affected Android device to the latest security patch released after January 5, 2018.
What devices are affected by CVE-2017-14906?
CVE-2017-14906 affects Qualcomm Snapdragon IoT and Snapdragon Mobile devices including MDM9206, MDM9607, and others as listed.
What impact does CVE-2017-14906 have on sensitive data?
The vulnerability in CVE-2017-14906 may lead to unauthorized access to sensitive data due to weaknesses in cryptographic storage.
Who reported CVE-2017-14906?
CVE-2017-14906 was reported by security researchers who identified the issues in Android's crypto storage APIs.