First published: Tue Sep 04 2018(Updated: )
Under certain mode of operations, HLOS may be able get direct or indirect access through DXE channels to tamper with the authenticated WCNSS firmware stored in DDR because DXE-accessible memory is located within the authenticated image in Snapdragon Mobile and Snapdragon Wear in version MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD 617.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm MSM8909W | ||
Qualcomm Snapdragon 8909 | ||
Qualcomm SD 210 Firmware | ||
Qualcomm SD 210 | ||
Qualcomm SD 212 Firmware | ||
Qualcomm SD 212 Firmware | ||
Qualcomm SD 205 Firmware | ||
Qualcomm SD 205 | ||
Qualcomm SD410 Firmware | ||
Qualcomm Snapdragon 410 | ||
Qualcomm SD 412 Firmware | ||
Qualcomm SD412 | ||
Qualcomm SD 615 Firmware | ||
Qualcomm Snapdragon 615 | ||
Qualcomm SD 616 Firmware | ||
Qualcomm Snapdragon 616 | ||
Qualcomm Snapdragon 415 Firmware | ||
Qualcomm Snapdragon 415 | ||
Qualcomm SD 617 Firmware | ||
Qualcomm QCA617 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18313 is classified as a high-severity vulnerability due to its potential for unauthorized access.
To fix CVE-2017-18313, ensure that your device firmware is updated to the latest version provided by the manufacturer.
CVE-2017-18313 affects devices utilizing Qualcomm MSM8909W firmware, including certain Android devices.
Yes, CVE-2017-18313 could potentially allow malware to tamper with authentication processes and gain unauthorized access.
Yes, CVE-2017-18313 primarily affects Qualcomm chipsets such as the MSM8909W and related devices.