CVE-2017-18317: Input Validation
Published Nov 5, 2018
·Updated
Restrictions related to the modem (sim lock, sim kill) can be bypassed by manipulating the system to issue a deactivation flow sequence in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996AU,SD 410/12,SD 820,SD 820A.
Affected Software
11 affected components
Google Android
Qualcomm Msm8996au Firmware
Qualcomm MSM8996AU
Qualcomm Sd 410 Firmware
Qualcomm SD 410
Qualcomm Sd 412 Firmware
Qualcomm Sd 412
Qualcomm Sd 820 Firmware
Qualcomm SD 820
Qualcomm Sd 820a Firmware
Qualcomm SD 820A
Event History
Nov 5, 2018
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Nov 28, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-18317?
The severity of CVE-2017-18317 is critical with a severity value of 7.8.
2
Which software versions are affected by CVE-2017-18317?
Qualcomm MSM8996AU, Snapdragon 410/12, Snapdragon 820, Snapdragon 820A are affected by CVE-2017-18317.
3
How can I fix CVE-2017-18317?
Apply the latest firmware updates provided by Qualcomm and Google for the affected software versions.
4
Where can I find more information about CVE-2017-18317?
You can find more information about CVE-2017-18317 in the Android Security Bulletin for November 2018 and the SecurityFocus BID 105838.