« Back to list

CVE-2017-18128

Status: ModifiedHigh (7.5)—

In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile SD 845, SD 850, improper access control while configuring MPU protecting error correction registers may potentially lead to exposure of related secured data.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2017-18128",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": true,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@qualcomm.com",
      "affectedData": [
        {
          "vendor": "Qualcomm, Inc.",
          "product": "Snapdragon Mobile",
          "versions": [
            {
              "status": "affected",
              "version": "SD 845, SD 850"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-04-11T15:29:00.663",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/103671",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "product-security@qualcomm.com"
    },
    {
      "url": "https://source.android.com/security/bulletin/2018-04-01",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@qualcomm.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/103671",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://source.android.com/security/bulletin/2018-04-01",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile SD 845, SD 850, improper access control while configuring MPU protecting error correction registers may potentially lead to exposure of related secured data."
    },
    {
      "lang": "es",
      "value": "En Android, antes del nivel de parche de seguridad del 2018-04-05 en Qualcomm Snapdragon Mobile SD 845, SD 850, el control de acceso incorrecto al configurar los registros de corrección de errores de protección MPU podría desembocar en la divulgación de datos relativos a la seguridad."
    }
  ],
  "lastModified": "2026-06-17T01:12:14.707",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qualcomm:sd_845_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A2D2B3B-CB28-46AA-9117-A7FA371FDE80"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:qualcomm:sd_845:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DE18BF66-B0DB-48BB-B43A-56F01821F5A3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qualcomm:sd_850_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C10C7CB-3B66-4F17-8146-6A85611E2BA9"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:qualcomm:sd_850:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B9DA765F-53DE-4FB0-B825-6C11B3177641"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "product-security@qualcomm.com"
}