CVE-2017-18321Sensitive Information Exposure in INC Snapdragon Mobile

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 84.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 3
Latest updateMay 14

Description

Security keys used by the terminal and NW for a session could be leaked in snapdragon mobile in versions MDM9650, MDM9655, SD 835, SDA660.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon_mobileMDM9650, MDM9655, SD 835, SDA660

🔴Vulnerability Details

1
GHSA
GHSA-92w7-7jg2-c4rc: Security keys used by the terminal and NW for a session could be leaked in snapdragon mobile in versions MDM9650, MDM9655, SD 835, SDA6602022-05-14

📋Vendor Advisories

1
Android
CVE-2017-18321: Closed-source component2018-12-01