CVE-2017-8248
published 2017-08-16CVE-2017-8248: A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as used in Apple iPhone 5 and later, iPad 4th generation and…
PriorityP344critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.07%
86.3th percentile
A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as used in Apple iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 10.3.2 | — |
| android | — | — | |
| qualcomm_inc | telephony | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2017-8248: Closed-source component
vendor_android·2018-12-01·CVSS 9.8
CVE-2017-8248 [CRITICAL] CVE-2017-8248: Closed-source component
Android Security Bulletin 2018-12-01
CVE: CVE-2017-8248
Severity: CRITICAL
Type: N/A
Component: Closed-source component
References: A-78135902*
Apple
CVE-2017-8248: iOS 10.3.3
vendor_apple·2017-07-19·CVSS 9.8
CVE-2017-8248 [CRITICAL] CVE-2017-8248: iOS 10.3.3
Apple Security Update: About the security content of iOS 10.3.3
Product: iOS
Version: 10.3.3
CVE: CVE-2017-8248
Component: CVE-2017-8248
GHSA
GHSA-jf2j-8329-vqx2: A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as used in Apple iPhone 5 and later, iPad 4th generation
ghsa_unreviewed·2022-05-14
CVE-2017-8248 [CRITICAL] CWE-119 GHSA-jf2j-8329-vqx2: A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as used in Apple iPhone 5 and later, iPad 4th generation
A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as used in Apple iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2017/Jul/34http://www.securityfocus.com/bid/106128http://www.securityfocus.com/bid/99891http://www.securitytracker.com/id/1038950http://seclists.org/fulldisclosure/2017/Jul/34http://www.securityfocus.com/bid/106128http://www.securityfocus.com/bid/99891http://www.securitytracker.com/id/1038950
2017-08-16
Published