Bypass Vulnerabilities in Snapdragon Automobile and Mobile Platforms
CVE-2017-18317

7.8HIGH

Key Information:

Vendor

Qualcomm

Vendor
CVE Published:
28 November 2018

What is CVE-2017-18317?

A series of vulnerabilities in Qualcomm's Snapdragon Automobile and Mobile products allow restriction mechanisms such as sim locks and sim kills to be circumvented. By manipulating the underlying system, an attacker could issue a deactivation flow sequence that disrupts these protections, potentially leading to unauthorized access and control over mobile connectivity functionalities. This vulnerability affects various versions of the Snapdragon platform, including MSM8996AU, SD 410/12, SD 820, and SD 820A, posing risks for users relying on these technologies.

Affected Version(s)

Snapdragon Automobile, Snapdragon Mobile MSM8996AU,SD 410/12,SD 820,SD 820A

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-18317 : Bypass Vulnerabilities in Snapdragon Automobile and Mobile Platforms