Lucene search

K
cveQualcommCVE-2015-9215
HistoryApr 18, 2018 - 2:29 p.m.

CVE-2015-9215

2018-04-1814:29:08
CWE-476
qualcomm
web.nvd.nist.gov
24
cve
android
qualcomm
usb
bootloader
null pointer
vulnerability
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.4

Confidence

High

EPSS

0.002

Percentile

56.1%

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, and SD 810, improper input validation can cause a null pointer dereference in USB bootloader find_ep() function.

Affected configurations

Nvd
Node
qualcommmdm9615_firmwareMatch-
AND
qualcommmdm9615Match-
Node
qualcommmdm9625_firmwareMatch-
AND
qualcommmdm9625Match-
Node
qualcommmdm9635m_firmwareMatch-
AND
qualcommmdm9635mMatch-
Node
qualcommsd_810_firmwareMatch-
AND
qualcommsd_810Match-
VendorProductVersionCPE
qualcommmdm9615_firmware-cpe:2.3:o:qualcomm:mdm9615_firmware:-:*:*:*:*:*:*:*
qualcommmdm9615-cpe:2.3:h:qualcomm:mdm9615:-:*:*:*:*:*:*:*
qualcommmdm9625_firmware-cpe:2.3:o:qualcomm:mdm9625_firmware:-:*:*:*:*:*:*:*
qualcommmdm9625-cpe:2.3:h:qualcomm:mdm9625:-:*:*:*:*:*:*:*
qualcommmdm9635m_firmware-cpe:2.3:o:qualcomm:mdm9635m_firmware:-:*:*:*:*:*:*:*
qualcommmdm9635m-cpe:2.3:h:qualcomm:mdm9635m:-:*:*:*:*:*:*:*
qualcommsd_810_firmware-cpe:2.3:o:qualcomm:sd_810_firmware:-:*:*:*:*:*:*:*
qualcommsd_810-cpe:2.3:h:qualcomm:sd_810:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Snapdragon Mobile",
    "vendor": "Qualcomm, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "MDM9615, MDM9625, MDM9635M, SD 810"
      }
    ]
  }
]

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.4

Confidence

High

EPSS

0.002

Percentile

56.1%

Related for CVE-2015-9215