Description
Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based device, the EFS partition can be erased. Apps processor then has non-secure world full read/write access to the partition until the modem boots and configures the EFS partition addresses in its MPU partition.
Published: 2018-07-06
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-3299 Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based device, the EFS partition can be erased. Apps processor then has non-secure world full read/write access to the partition until the modem boots and configures the EFS partition addresses in its MPU partition.
History

No history.

Subscriptions

Qualcomm Mdm9206 Mdm9206 Firmware Mdm9607 Mdm9607 Firmware Mdm9635m Mdm9635m Firmware Mdm9640 Mdm9640 Firmware Mdm9650 Mdm9650 Firmware Mdm9655 Mdm9655 Firmware Msm8909w Msm8909w Firmware Msm8996au Msm8996au Firmware Sd 205 Sd 205 Firmware Sd 210 Sd 210 Firmware Sd 212 Sd 212 Firmware Sd 410 Sd 410 Firmware Sd 412 Sd 412 Firmware Sd 415 Sd 415 Firmware Sd 425 Sd 425 Firmware Sd 427 Sd 427 Firmware Sd 430 Sd 430 Firmware Sd 435 Sd 435 Firmware Sd 450 Sd 450 Firmware Sd 615 Sd 615 Firmware Sd 616 Sd 616 Firmware Sd 617 Sd 617 Firmware Sd 625 Sd 625 Firmware Sd 650 Sd 650 Firmware Sd 652 Sd 652 Firmware Sd 800 Sd 800 Firmware Sd 810 Sd 810 Firmware Sd 820 Sd 820 Firmware Sd 820a Sd 820a Firmware Sd 835 Sd 835 Firmware Sd 845 Sd 845 Firmware Sd 850 Sd 850 Firmware Sdm630 Sdm630 Firmware Sdm632 Sdm632 Firmware Sdm636 Sdm636 Firmware Sdm660 Sdm660 Firmware Sdx20 Sdx20 Firmware Snapdragon High Med 2016 Snapdragon High Med 2016 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2024-09-17T00:57:03.674Z

Reserved: 2018-05-18T00:00:00.000Z

Link: CVE-2018-11259

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-07-06T17:29:00.757

Modified: 2024-11-21T03:43:00.527

Link: CVE-2018-11259

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses