// For flags

CVE-2017-18173

 

Severity Score

7.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In case of using an invalid android verified boot signature with very large length, an integer underflow occurs in Snapdragon Mobile in SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 810, SD 820, SD 835, SDM630, SDM636, SDM660, Snapdragon_High_Med_2016.

En caso de utilizar una firma de arranque verificada por Android no vĂ¡lida con una longitud muy grande, se produce un subdesbordamiento de enteros en Snapdragon Mobile en SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 810, SD 820, SD 835, SDM630, SDM636, SDM660, Snapdragon_High_Med_2016.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-02-05 CVE Reserved
  • 2019-05-06 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-190: Integer Overflow or Wraparound
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Qualcomm
Search vendor "Qualcomm"
Sd 425 Firmware
Search vendor "Qualcomm" for product "Sd 425 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Sd 425
Search vendor "Qualcomm" for product "Sd 425"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Sd 427 Firmware
Search vendor "Qualcomm" for product "Sd 427 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Sd 427
Search vendor "Qualcomm" for product "Sd 427"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Sd 430 Firmware
Search vendor "Qualcomm" for product "Sd 430 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Sd 430
Search vendor "Qualcomm" for product "Sd 430"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Sd 435 Firmware
Search vendor "Qualcomm" for product "Sd 435 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Sd 435
Search vendor "Qualcomm" for product "Sd 435"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Sd 450 Firmware
Search vendor "Qualcomm" for product "Sd 450 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Sd 450
Search vendor "Qualcomm" for product "Sd 450"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Sd 625 Firmware
Search vendor "Qualcomm" for product "Sd 625 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Sd 625
Search vendor "Qualcomm" for product "Sd 625"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Sd 810 Firmware
Search vendor "Qualcomm" for product "Sd 810 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Sd 810
Search vendor "Qualcomm" for product "Sd 810"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Sd 820 Firmware
Search vendor "Qualcomm" for product "Sd 820 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Sd 820
Search vendor "Qualcomm" for product "Sd 820"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Sd 835 Firmware
Search vendor "Qualcomm" for product "Sd 835 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Sd 835
Search vendor "Qualcomm" for product "Sd 835"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Sdm630 Firmware
Search vendor "Qualcomm" for product "Sdm630 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Sdm630
Search vendor "Qualcomm" for product "Sdm630"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Sdm636 Firmware
Search vendor "Qualcomm" for product "Sdm636 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Sdm636
Search vendor "Qualcomm" for product "Sdm636"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Sdm660 Firmware
Search vendor "Qualcomm" for product "Sdm660 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Sdm660
Search vendor "Qualcomm" for product "Sdm660"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Snapdragon High Med 2016 Firmware
Search vendor "Qualcomm" for product "Snapdragon High Med 2016 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Snapdragon High Med 2016
Search vendor "Qualcomm" for product "Snapdragon High Med 2016"
--
Safe