CVE-2017-18160: Critical severity android vulnerability
AGPS session failure in GNSS module due to cyphersuites are hardcoded and needed manual update everytime in snapdragon mobile and snapdragon wear in versions MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 835, SD 845, SD 850
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18160?
CVE-2017-18160 has been classified with a medium severity rating due to potential impacts on AGPS session failures.
How do I fix CVE-2017-18160?
To fix CVE-2017-18160, manually update the hardcoded cyphersuites in the affected Snapdragon firmware versions.
Which devices are affected by CVE-2017-18160?
CVE-2017-18160 affects devices using Snapdragon mobile and wear chipsets, including MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 835, SD 845, and SD 850.
What types of attacks can CVE-2017-18160 enable?
CVE-2017-18160 may potentially allow attackers to intercept or manipulate GPS data due to session failures.
Is CVE-2017-18160 related to Google Android?
Yes, CVE-2017-18160 impacts Google Android systems that utilize the specified Snapdragon chipsets.