CRITICAL🇵🇱 Wersja polska

CVE-2017-17772

CVSS 9.8v3.1pub. 2024-11-26upd. 2025-01-09

In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.

🤖 AI Analysis
How it works

Many functions responsible for processing 802.11 (Wi-Fi) standard frames lack proper input data validation. Insufficient buffer boundary control (CWE-125 — out-of-bounds read, CWE-126 — buffer over-read) allows reading data outside the intended memory area. Specially crafted Wi-Fi frames sent to a vulnerable device can trigger this error without any user interaction.

Impact

An attacker within wireless network range can gain unauthorized access to sensitive data stored in device memory, and in extreme cases compromise the confidentiality, integrity, and availability of the system.

Mitigation & patch

Apply patches available from the vendor according to the references — Qualcomm security bulletin from May 2018: https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html. OEM device manufacturers using the mentioned chipsets should deploy firmware updates for their products.

Who is affected

Firmware of Qualcomm SD 450, Qualcomm SD 625, and Qualcomm SD 820 chipsets — versions indicated in the vendor's references (Qualcomm security bulletin from May 2018)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Qualcomm Sd 450

    HW
    Qualcomm
    all versions
  • Qualcomm Sd 450 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Sd 625

    HW
    Qualcomm
    all versions
  • Qualcomm Sd 625 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Sd 820

    HW
    Qualcomm
    all versions
  • Qualcomm Sd 820a

    HW
    Qualcomm
    all versions
  • Qualcomm Sd 820a Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Sd 820 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Sd 835

    HW
    Qualcomm
    all versions
  • Qualcomm Sd 835 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Sd 845

    HW
    Qualcomm
    all versions
  • Qualcomm Sd 845 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Sd 850

    HW
    Qualcomm
    all versions
  • Qualcomm Sd 850 Firmware

    OS
    Qualcomm
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2017-11076CRITICAL9.8PL ✓same product

Qualcomm: Nieprawidłowy dostęp do pamięci przy dekodowaniu VP9 (sprzętowe)

CVE-2018-11922CRITICAL9.8PL ✓same product

Qualcomm Touch Pal – zbieranie danych o użytkowniku bez jego wiedzy

CVE-2019-10505CRITICAL9.8PL ✓same product

Qualcomm Snapdragon: out-of-bounds read przy przetwarzaniu IE w ramkach pomiarowych

CVE-2019-10522CRITICAL9.8PL ✓same product

Buffer overflow w parserze multimediów Qualcomm — podatność krytyczna

CVE-2019-10528CRITICAL9.8PL ✓same product

Use-after-free w kernelu Qualcomm — dostęp do zwolnionych sesji mdlog