CVE-2017-18293
Status: ModifiedHigh (7.8)—
When a particular GPIO is protected by blocking access to the corresponding GPIO resource registers, the protection can be bypassed using the corresponding banked GPIO registers instead in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 835, SDA660.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Base score: 7.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.26%
- Percentile among all scored CVEs: 16
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (14)
Qualcomm — Mdm9206 FirmwareQualcomm — Mdm9607 FirmwareQualcomm — Mdm9650 FirmwareQualcomm — SD 205 FirmwareQualcomm — SD 210 FirmwareQualcomm — SD 212 FirmwareQualcomm — SD 425 FirmwareQualcomm — SD 430 FirmwareQualcomm — SD 450 FirmwareQualcomm — SD 625 FirmwareQualcomm — SD 650 FirmwareQualcomm — SD 652 FirmwareQualcomm — SD 835 FirmwareQualcomm — Sda660 Firmware
CWEs
- NVD-CWE-noinfo
References
- http://www.securitytracker.com/id/1041432
- https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-components
- https://www.qualcomm.com/company/product-security/bulletins
- http://www.securitytracker.com/id/1041432
- https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-components
- https://www.qualcomm.com/company/product-security/bulletins
Raw JSON (NVD)
Show
{
"id": "CVE-2017-18293",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": true,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "product-security@qualcomm.com",
"affectedData": [
{
"vendor": "Qualcomm, Inc.",
"product": "Snapdragon Mobile, Snapdragon Wear",
"versions": [
{
"status": "affected",
"version": "MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 835, SDA660"
}
]
}
]
}
],
"published": "2018-10-23T13:29:01.260",
"references": [
{
"url": "http://www.securitytracker.com/id/1041432",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "product-security@qualcomm.com"
},
{
"url": "https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-components",
"tags": [
"Third Party Advisory"
],
"source": "product-security@qualcomm.com"
},
{
"url": "https://www.qualcomm.com/company/product-security/bulletins",
"tags": [
"Vendor Advisory"
],
"source": "product-security@qualcomm.com"
},
{
"url": "http://www.securitytracker.com/id/1041432",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-components",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.qualcomm.com/company/product-security/bulletins",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "When a particular GPIO is protected by blocking access to the corresponding GPIO resource registers, the protection can be bypassed using the corresponding banked GPIO registers instead in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 835, SDA660."
},
{
"lang": "es",
"value": "Cuando un GPIO en concreto está protegido bloqueando el acceso a los registros de recursos GPIO correspondientes, la protección se puede omitir mediante los registros GPIO correspondientes en su lugar en Snapdragon Mobile y Snapdragon Wear en versiones MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 835 y SDA660."
}
],
"lastModified": "2026-06-17T01:12:33.970",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A960B86A-C397-4ACB-AEE6-55F316D32949"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:mdm9206:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D79B8959-3D1E-4B48-9181-D75FE90AAF98"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A35FECFB-60AE-42A8-BCBB-FEA7D5826D49"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:mdm9607:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E9765187-8653-4D66-B230-B2CE862AC5C0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:mdm9650_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35B7E25E-FA92-4C36-883C-CFF36F4B3507"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:mdm9650:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "ECD99C6F-2444-4A5E-A517-0C8023DDF23D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_210_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0FA80D57-3191-47CF-AD3F-9F2D64E443FE"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_210:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B2AFB212-F01A-4CEB-8DB4-2E0CC2308CB6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_212_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0986EF1-0974-488E-84C4-6880F876CE55"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_212:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8C08BA58-2EBC-4A22-85A4-2ECD54693B9B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_205_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "27110478-4C08-49E6-BD53-8BAAD9D5BD65"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_205:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3664D302-D22A-4B25-B534-3097AE2F8573"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_425_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C56BC939-2FE8-4AB4-B638-35C83B224005"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_425:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E36C12E2-7064-41E6-B357-3F0E6E6D0A0F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_430_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE5C66CC-B00C-4581-B8FB-0632232E480D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_430:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "87F57247-08CD-473E-A517-F9E85BFC7BEA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_450_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E07C621F-0BC0-40C1-9678-1AF6498AC487"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_450:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9C621A62-E346-406B-9D20-8FF6C2B0851F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_625_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "06E0CC35-AC20-42D7-8FEA-CA4685E33E72"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_625:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4A2C4DED-2367-4736-A0AF-C8356F1271AD"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_650_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC1650DB-FDF8-4BE5-9437-8ADA11A07116"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_650:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B51DD51F-4BDE-497B-89E5-551D10CF3442"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_652_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0752054B-2C29-4490-ADC8-29F82BAA17E6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_652:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "005038B5-BCB7-4A23-8562-ACEF6E156C1F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_835_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1CFF35A3-1472-4665-9DAB-1ABC45C0D5B4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_835:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F930E9BF-C502-49C6-8BE8-9A711B89FA1B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sda660_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A2326BD7-28A5-4244-8501-B109913E7AE6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sda660:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "532D244B-8B5A-4923-B7F1-9DC0A5FC0E9D"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "product-security@qualcomm.com"
}