First published: Mon Aug 06 2018(Updated: )
In Snapdragon (Automobile, Mobile, Wear) in version MDM9607, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDM429, SDM439, SDM632, Snapdragon_High_Med_2016, when a Trusted Application has opened the SPI/I2C interface to a particular device, it is possible for another Trusted Application to read the data on this open interface by calling the SPI/I2C read function.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Mdm9607 Firmware | ||
Qualcomm Mdm9607 | ||
Qualcomm Msm8909w Firmware | ||
Qualcomm Msm8909w | ||
Qualcomm Msm8996au Firmware | ||
Qualcomm Msm8996au | ||
Qualcomm Sd210 Firmware | ||
Qualcomm Sd210 | ||
Qualcomm Sd212 Firmware | ||
Qualcomm Sd212 | ||
Qualcomm Sd205 Firmware | ||
Qualcomm Sd205 | ||
Qualcomm Sd425 Firmware | ||
Qualcomm Sd425 | ||
Qualcomm Sd427 Firmware | ||
Qualcomm Sd427 | ||
Qualcomm Sd430 Firmware | ||
Qualcomm Sd430 | ||
Qualcomm Sd435 Firmware | ||
Qualcomm Sd435 | ||
Qualcomm Sd450 Firmware | ||
Qualcomm Sd450 | ||
Qualcomm Sd617 Firmware | ||
Qualcomm Sd617 | ||
Qualcomm Sd625 Firmware | ||
Qualcomm Sd625 | ||
Qualcomm Sd650 Firmware | ||
Qualcomm Sd650 | ||
Qualcomm Sd652 Firmware | ||
Qualcomm Sd652 | ||
Qualcomm Sd820 Firmware | ||
Qualcomm Sd820 | ||
Qualcomm Sd820a Firmware | ||
Qualcomm Sd820a | ||
Qualcomm Sd835 Firmware | ||
Qualcomm Sd835 | ||
Qualcomm Sdm429 Firmware | ||
Qualcomm Sdm429 | ||
Qualcomm Sdm439 Firmware | ||
Qualcomm Sdm439 | ||
Qualcomm Sdm632 Firmware | ||
Qualcomm Sdm632 | ||
Google Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2017-18280.
This vulnerability affects Snapdragon (Automobile, Mobile, Wear) in version MDM9607, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDM429, SDM439, SDM632, Snapdragon_High_Med_2016.
The severity of CVE-2017-18280 is rated as high, with a severity value of 7.8.
To fix the vulnerability in Snapdragon devices, it is recommended to apply the security patches provided by Qualcomm or the device manufacturer.
You can find more information about CVE-2017-18280 on the Android Security Bulletin for August 2018: https://source.android.com/docs/security/bulletin/2018-08-01/#asterisk