Improper Authorization in Qualcomm Snapdragon Products
CVE-2017-8276

7.8HIGH

Key Information:

Vendor
Qualcomm
Vendor
CVE Published:
18 January 2019

Summary

An improper authorization vulnerability exists in the Qualcomm Snapdragon TrustZone that could allow an attacker to bypass security measures. This issue affects various Snapdragon products, including mobile and automotive platforms. Attackers leveraging this vulnerability may gain unauthorized access, which compromises user data and device security. Given the extensive use of Snapdragon chips, the implications of this vulnerability are significant and warrant prompt attention from users and developers.

Affected Version(s)

Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear MDM9206, MDM9607, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SDA660, SDM439, SDM630, SDM660, SDX24, Snapdragon_High_Med_2016

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.