CVE-2017-18332: Infoleak
Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX20, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18332?
The severity of CVE-2017-18332 is high (5.5).
What is CVE-2017-18332?
CVE-2017-18332 is a vulnerability that allows security keys to be logged when configuring or reconfiguring WCDMA calls in Snapdragon devices running certain software versions.
Which Qualcomm products are affected by CVE-2017-18332?
Qualcomm products MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 712, and SD 710 are affected by CVE-2017-18332.
How can I fix CVE-2017-18332?
To fix CVE-2017-18332, apply the necessary patches and updates provided by Qualcomm or the Android operating system.
Where can I find more information about CVE-2017-18332?
You can find more information about CVE-2017-18332 on the Android Security Bulletin for December 2018.