{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-02T02:31:03.888","vulnerabilities":[{"cve":{"id":"CVE-2017-18302","sourceIdentifier":"product-security@qualcomm.com","published":"2018-09-20T13:29:00.510","lastModified":"2024-11-21T03:19:48.723","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016, a crafted HLOS client can modify the structure in memory passed to a QSEE application between the time of check and the time of use, resulting in arbitrary writes to TZ kernel memory regions."},{"lang":"es","value":"En Snapdragon (Automobile y Mobile) en versiones MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660 y Snapdragon_High_Med_2016, un cliente HLOS manipulado puede modificar la estructura en la memoria pasada a una aplicación QSEE entre el momento de la comprobación y el momento del uso, lo que desemboca en escrituras arbitrarias a las regiones de memoria del kernel TZ."}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:N/I:C/A:N","baseScore":4.7,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"COMPLETE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.4,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-362"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:msm8996au_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"8CA1E7B0-782B-4757-B118-802943798984"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:msm8996au:-:*:*:*:*:*:*:*","matchCriteriaId":"95CB08EC-AE12-4A54-AA3C-998F01FC8763"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sd425_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"BC5ECC0E-0120-47E5-9D00-440DC38F2C0B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sd425:-:*:*:*:*:*:*:*","matchCriteriaId":"352E745F-375B-43AE-9B29-8A2D50C695B4"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sd427_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"C9CDD792-89BC-4A7B-A971-4C04663E62A7"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sd427:-:*:*:*:*:*:*:*","matchCriteriaId":"64D6ACA2-47C7-4E44-A838-22600B5BC52E"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sd430_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"F6652C54-B207-4816-B70D-5DD2C792D1DF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sd430:-:*:*:*:*:*:*:*","matchCriteriaId":"FD3B99CC-CC53-42A6-9C42-0C06E734A554"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sd435_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"7C2951AF-E04B-433B-B327-03D8D28B2BDE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sd435:-:*:*:*:*:*:*:*","matchCriteriaId":"084BB475-8F09-408E-AF1C-D0CA4DD8D414"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sd450_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"BF6EA9F3-ED14-4DAC-93D1-2DF63C7C3EAC"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sd450:-:*:*:*:*:*:*:*","matchCriteriaId":"C4EF0B75-2431-4E44-B515-11C9BD4BC982"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sd625_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"7C5E72A3-2117-4190-978F-EFB4DDE4EC9F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sd625:-:*:*:*:*:*:*:*","matchCriteriaId":"AD2EEF23-73EB-49AE-B9F1-4702D545D643"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sd650_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"3A83A1CF-396D-403F-AA22-0ED817DD384B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sd650:-:*:*:*:*:*:*:*","matchCriteriaId":"21AEAA09-3C1B-4413-8418-63644DB3FABA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sd652_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"E6C536B0-32E9-42D0-B298-B4D77CC94914"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sd652:-:*:*:*:*:*:*:*","matchCriteriaId":"8F81E096-820A-4B27-A539-5D3BA39FA5C9"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sd820_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"BC508C49-0B76-43A8-B2AF-0F8EB989E238"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sd820:-:*:*:*:*:*:*:*","matchCriteriaId":"E9665200-D306-4EEB-9F42-6C5963524179"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sd820a_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"CB757118-0F90-4E6E-AD4F-A05A5791B20C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sd820a:-:*:*:*:*:*:*:*","matchCriteriaId":"2BCD9420-26A7-4444-9AA4-D7B0AC42FA84"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sd835_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"9DA605FD-B801-43BB-B52D-879013F7F57E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sd835:-:*:*:*:*:*:*:*","matchCriteriaId":"908BFD96-0423-4AFC-B8F3-105B2D5B4C73"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sda660_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"A2326BD7-28A5-4244-8501-B109913E7AE6"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sda660:-:*:*:*:*:*:*:*","matchCriteriaId":"532D244B-8B5A-4923-B7F1-9DC0A5FC0E9D"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sdm429_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"9DFD2C9A-6C25-4B8F-BE64-DAD3DCCDEADD"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sdm429:-:*:*:*:*:*:*:*","matchCriteriaId":"8DE61FCE-CA87-46E1-981D-B44697E54CB1"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sdm439_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"84289E6D-DA2A-4D04-9DDA-E8C46DDDD056"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sdm439:-:*:*:*:*:*:*:*","matchCriteriaId":"C0B56360-7AC3-410A-B7F8-1BE8514B3781"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sdm630_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"8EA0D645-80F6-48C3-AF0D-99198ADC8778"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sdm630:-:*:*:*:*:*:*:*","matchCriteriaId":"814FF3F3-CD5A-45A3-988C-6457D2CEB48C"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sdm632_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"A02E12AC-F845-4164-9D95-ACD7167B6DD6"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sdm632:-:*:*:*:*:*:*:*","matchCriteriaId":"321F7DE7-E6E9-449F-867B-04A9F53334B0"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sdm636_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"8F00D854-0AC7-415F-B19A-642CB9F72210"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sdm636:-:*:*:*:*:*:*:*","matchCriteriaId":"F977B432-2709-4D75-AA3E-F440285B7BA2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qualcomm:sdm660_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"24D7B67C-6FEC-48F8-9D46-778E4528BC20"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qualcomm:sdm660:-:*:*:*:*:*:*:*","matchCriteriaId":"05006807-D961-446C-B8DC-C87507F1316E"}]}]}],"references":[{"url":"http://www.securitytracker.com/id/1041432","source":"product-security@qualcomm.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-components","source":"product-security@qualcomm.com","tags":["Vendor Advisory"]},{"url":"https://www.qualcomm.com/company/product-security/bulletins","source":"product-security@qualcomm.com","tags":["Vendor Advisory"]},{"url":"http://www.securitytracker.com/id/1041432","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-components","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.qualcomm.com/company/product-security/bulletins","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}