ID

VAR-201905-0650


CVE

CVE-2017-15841


TITLE

plural Snapdragon Authorization vulnerabilities in products

Trust: 0.8

sources: JVNDB: JVNDB-2017-014451

DESCRIPTION

When HOST sends a Special command ID packet, Controller triggers a RAM Dump and FW reset in Snapdragon Mobile in version SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 835, Snapdragon_High_Med_2016. plural Snapdragon The product contains an authorization vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. QualcommSD410 and others are a central processing unit (CPU) product of Qualcomm. An authorization vulnerability exists in the BluetoothController in several Qualcomm products that can be exploited by an attacker to trigger a RAMDump and FW reset. Qualcomm Closed-Source Components are prone to multiple unspecified vulnerabilities. An attacker can exploit these issues to perform unauthorized actions. This may aid in further attacks. These issues are being tracked by Android Bug IDs A-78240792, A-78240715, A-78240449, A-78240612, A-78240794, A-78240199, A-78240071, A-78240736, A-78242049, A-78241971, A-78241834, A-78241375, A-68989823, A-72951265, A-74235874, A-74236406, A-77485022, A-77485183, A-77485139, A-77483830, and A-77484449. This vulnerability stems from the lack of authentication measures or insufficient authentication strength in network systems or products

Trust: 2.61

sources: NVD: CVE-2017-15841 // JVNDB: JVNDB-2017-014451 // CNVD: CNVD-2019-14817 // BID: 104760 // VULHUB: VHN-106704 // VULMON: CVE-2017-15841

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-14817

AFFECTED PRODUCTS

vendor:qualcommmodel:sd 820scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 450scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 616scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 415scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 427scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 435scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 412scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 835scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 652scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 425scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 430scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:snapdragon high med 2016scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 410scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 625scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 615scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 410scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 412scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 415scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 425scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 427scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 430scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 435scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 450scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 615scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 616scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sdscope:eqversion:425

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:450

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:615/16

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:415

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:625

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:650/52

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:820

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:835

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:430

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:410/12

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:427

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:435

Trust: 0.6

vendor:qualcommmodel:snapdragon high med 2016scope: - version: -

Trust: 0.6

vendor:googlemodel:pixel xlscope:eqversion:0

Trust: 0.3

vendor:googlemodel:pixel cscope:eqversion:0

Trust: 0.3

vendor:googlemodel:pixelscope:eqversion:0

Trust: 0.3

vendor:googlemodel:nexus playerscope:eqversion:0

Trust: 0.3

vendor:googlemodel:nexusscope:eqversion:9

Trust: 0.3

vendor:googlemodel:nexus 6pscope: - version: -

Trust: 0.3

vendor:googlemodel:nexusscope:eqversion:6

Trust: 0.3

vendor:googlemodel:nexusscope:eqversion:5x

Trust: 0.3

vendor:googlemodel:androidscope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2019-14817 // BID: 104760 // JVNDB: JVNDB-2017-014451 // NVD: CVE-2017-15841

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-15841
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-15841
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2019-14817
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201905-140
value: MEDIUM

Trust: 0.6

VULHUB: VHN-106704
value: MEDIUM

Trust: 0.1

VULMON: CVE-2017-15841
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-15841
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2019-14817
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-106704
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-15841
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2019-14817 // VULHUB: VHN-106704 // VULMON: CVE-2017-15841 // JVNDB: JVNDB-2017-014451 // CNNVD: CNNVD-201905-140 // NVD: CVE-2017-15841

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-285

Trust: 0.9

sources: VULHUB: VHN-106704 // JVNDB: JVNDB-2017-014451 // NVD: CVE-2017-15841

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201905-140

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201905-140

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-014451

PATCH

title:August 2018 Qualcomm Technologies, Inc. Security Bulletinurl:https://www.qualcomm.com/company/product-security/bulletins

Trust: 0.8

title:Patches for multiple Qualcomm product licensing issuesurl:https://www.cnvd.org.cn/patchInfo/show/161667

Trust: 0.6

title:Multiple Qualcomm Product Authorization Issue Vulnerability Fixing Measuresurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=92287

Trust: 0.6

title:Android Security Bulletins: Android Security Bulletin—July 2018url:https://vulmon.com/vendoradvisory?qidtp=android_security_bulletins&qid=25584b3d319ca9e7cb2fae9ec5dbf5e0

Trust: 0.1

title:SamsungReleaseNotesurl:https://github.com/samreleasenotes/SamsungReleaseNotes

Trust: 0.1

sources: CNVD: CNVD-2019-14817 // VULMON: CVE-2017-15841 // JVNDB: JVNDB-2017-014451 // CNNVD: CNNVD-201905-140

EXTERNAL IDS

db:NVDid:CVE-2017-15841

Trust: 3.5

db:JVNDBid:JVNDB-2017-014451

Trust: 0.8

db:CNNVDid:CNNVD-201905-140

Trust: 0.7

db:CNVDid:CNVD-2019-14817

Trust: 0.6

db:BIDid:104760

Trust: 0.3

db:VULHUBid:VHN-106704

Trust: 0.1

db:VULMONid:CVE-2017-15841

Trust: 0.1

sources: CNVD: CNVD-2019-14817 // VULHUB: VHN-106704 // VULMON: CVE-2017-15841 // BID: 104760 // JVNDB: JVNDB-2017-014451 // CNNVD: CNNVD-201905-140 // NVD: CVE-2017-15841

REFERENCES

url:https://www.qualcomm.com/company/product-security/bulletins

Trust: 2.4

url:https://nvd.nist.gov/vuln/detail/cve-2017-15841

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-15841

Trust: 0.8

url:https://web.nvd.nist.gov//vuln/detail/cve-2017-15841

Trust: 0.6

url:http://code.google.com/android/

Trust: 0.3

url:http://www.qualcomm.com/

Trust: 0.3

url:https://source.android.com/security/bulletin/2018-07-01

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://source.android.com/security/bulletin/2018-07-01.html

Trust: 0.1

url:https://github.com/samreleasenotes/samsungreleasenotes

Trust: 0.1

sources: CNVD: CNVD-2019-14817 // VULHUB: VHN-106704 // VULMON: CVE-2017-15841 // BID: 104760 // JVNDB: JVNDB-2017-014451 // CNNVD: CNNVD-201905-140 // NVD: CVE-2017-15841

CREDITS

The vendor reported these issues.

Trust: 0.3

sources: BID: 104760

SOURCES

db:CNVDid:CNVD-2019-14817
db:VULHUBid:VHN-106704
db:VULMONid:CVE-2017-15841
db:BIDid:104760
db:JVNDBid:JVNDB-2017-014451
db:CNNVDid:CNNVD-201905-140
db:NVDid:CVE-2017-15841

LAST UPDATE DATE

2024-11-23T21:38:37.790000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-14817date:2019-05-21T00:00:00
db:VULHUBid:VHN-106704date:2019-10-03T00:00:00
db:VULMONid:CVE-2017-15841date:2019-10-03T00:00:00
db:BIDid:104760date:2018-07-02T00:00:00
db:JVNDBid:JVNDB-2017-014451date:2019-05-31T00:00:00
db:CNNVDid:CNNVD-201905-140date:2019-10-23T00:00:00
db:NVDid:CVE-2017-15841date:2024-11-21T03:15:19.120

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-14817date:2019-05-21T00:00:00
db:VULHUBid:VHN-106704date:2019-05-06T00:00:00
db:VULMONid:CVE-2017-15841date:2019-05-06T00:00:00
db:BIDid:104760date:2018-07-02T00:00:00
db:JVNDBid:JVNDB-2017-014451date:2019-05-31T00:00:00
db:CNNVDid:CNNVD-201905-140date:2019-05-06T00:00:00
db:NVDid:CVE-2017-15841date:2019-05-06T23:29:00.220