Lucene search

K
cveQualcommCVE-2014-10047
HistoryApr 18, 2018 - 2:29 p.m.

CVE-2014-10047

2018-04-1814:29:00
CWE-200
qualcomm
web.nvd.nist.gov
25
android
security patch
qualcomm snapdragon
mobile
sd 400
sd 800
information leak
full disk encryption
cve-2014-10047
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

39.1%

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, when writing the Full Disk Encryption key to crypto engine, information leak could occur.

Affected configurations

Nvd
Node
qualcommsd_400_firmwareMatch-
AND
qualcommsd_400Match-
Node
qualcommsd_800_firmwareMatch-
AND
qualcommsd_800Match-
VendorProductVersionCPE
qualcommsd_400_firmware-cpe:2.3:o:qualcomm:sd_400_firmware:-:*:*:*:*:*:*:*
qualcommsd_400-cpe:2.3:h:qualcomm:sd_400:-:*:*:*:*:*:*:*
qualcommsd_800_firmware-cpe:2.3:o:qualcomm:sd_800_firmware:-:*:*:*:*:*:*:*
qualcommsd_800-cpe:2.3:h:qualcomm:sd_800:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Snapdragon Mobile",
    "vendor": "Qualcomm, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "SD 400, SD 800"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

39.1%

Related for CVE-2014-10047