First published: Mon Aug 06 2018(Updated: )
In Snapdragon (Automobile, Mobile, Wear) in version MDM9607, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDM429, SDM439, SDM632, Snapdragon_High_Med_2016, when a Trusted Application has opened the SPI/I2C interface to a particular device, it is possible for another Trusted Application to read the data on this open interface by calling the SPI/I2C read function.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm MD9607 Firmware | ||
Qualcomm MDM9607 firmware | ||
Qualcomm 8909 Firmware | ||
Qualcomm Snapdragon 8909 | ||
qualcomm MSM8996AU firmware | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm SD 210 Firmware | ||
Qualcomm SD210 Firmware | ||
Qualcomm SD 212 Firmware | ||
Qualcomm SD 212 | ||
Qualcomm 205 Firmware | ||
Qualcomm Snapdragon 205 | ||
Qualcomm SD425 Firmware | ||
Qualcomm Snapdragon 425 | ||
Qualcomm SD 427 firmware | ||
Qualcomm SD427 Firmware | ||
Qualcomm SD 430 Firmware | ||
Qualcomm Snapdragon 430 | ||
Qualcomm Snapdragon 435 Firmware | ||
Qualcomm Snapdragon 435 | ||
Qualcomm SD 450 Firmware | ||
Qualcomm Snapdragon 450 | ||
Qualcomm SD 617 Firmware | ||
Qualcomm QCA617 | ||
Qualcomm SD 625 Firmware | ||
Qualcomm Snapdragon 625 | ||
Qualcomm SD 650 Firmware | ||
Qualcomm Snapdragon 650 | ||
Qualcomm SD 652 Firmware | ||
Qualcomm SD652 Firmware | ||
Qualcomm SD 820 Firmware | ||
Qualcomm Snapdragon 820 | ||
Qualcomm SD 820A firmware | ||
Qualcomm SD820A Firmware | ||
Qualcomm Snapdragon 835 | ||
Qualcomm Snapdragon 835 | ||
Qualcomm SDM429W | ||
Qualcomm SD429 | ||
Qualcomm SDM439 Firmware | ||
Qualcomm SDM439 Firmware | ||
Qualcomm SDM632 Firmware | ||
Qualcomm SDM632 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2017-18280.
This vulnerability affects Snapdragon (Automobile, Mobile, Wear) in version MDM9607, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDM429, SDM439, SDM632, Snapdragon_High_Med_2016.
The severity of CVE-2017-18280 is rated as high, with a severity value of 7.8.
To fix the vulnerability in Snapdragon devices, it is recommended to apply the security patches provided by Qualcomm or the device manufacturer.
You can find more information about CVE-2017-18280 on the Android Security Bulletin for August 2018: https://source.android.com/docs/security/bulletin/2018-08-01/#asterisk