XBL sec mem dump system call allows complete control of EL3 by unlocking all XPUs if enable fuse is not blown in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835.
References
Link | Resource |
---|---|
http://www.securitytracker.com/id/1041432 | Third Party Advisory VDB Entry |
https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-components | Third Party Advisory |
https://www.qualcomm.com/company/product-security/bulletins | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
History
No history.
Information
Published : 2018-10-23 13:29
Updated : 2024-02-04 20:03
NVD link : CVE-2017-18305
Mitre link : CVE-2017-18305
CVE.ORG link : CVE-2017-18305
JSON object : View
Products Affected
qualcomm
- sd_212
- sd_205_firmware
- sd_210
- mdm9650_firmware
- sd_212_firmware
- sd_835_firmware
- mdm9206_firmware
- sd_835
- sd_205
- mdm9206
- sd_210_firmware
- mdm9607_firmware
- mdm9650
- mdm9607
CWE