Description
In Snapdragon (Automobile, Mobile, Wear) in version MDM9607, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDM429, SDM439, SDM632, Snapdragon_High_Med_2016, when a Trusted Application has opened the SPI/I2C interface to a particular device, it is possible for another Trusted Application to read the data on this open interface by calling the SPI/I2C read function.
Published: 2018-09-20
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-9407 In Snapdragon (Automobile, Mobile, Wear) in version MDM9607, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDM429, SDM439, SDM632, Snapdragon_High_Med_2016, when a Trusted Application has opened the SPI/I2C interface to a particular device, it is possible for another Trusted Application to read the data on this open interface by calling the SPI/I2C read function.
History

No history.

Subscriptions

Qualcomm Mdm9607 Mdm9607 Firmware Msm8909w Msm8909w Firmware Msm8996au Msm8996au Firmware Sd205 Sd205 Firmware Sd210 Sd210 Firmware Sd212 Sd212 Firmware Sd425 Sd425 Firmware Sd427 Sd427 Firmware Sd430 Sd430 Firmware Sd435 Sd435 Firmware Sd450 Sd450 Firmware Sd617 Sd617 Firmware Sd625 Sd625 Firmware Sd650 Sd650 Firmware Sd652 Sd652 Firmware Sd820 Sd820 Firmware Sd820a Sd820a Firmware Sd835 Sd835 Firmware Sdm429 Sdm429 Firmware Sdm439 Sdm439 Firmware Sdm632 Sdm632 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2024-08-05T21:13:49.271Z

Reserved: 2018-05-18T00:00:00.000Z

Link: CVE-2017-18280

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-09-20T13:29:00.247

Modified: 2024-11-21T03:19:45.513

Link: CVE-2017-18280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses