Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gmrf-7wh2-5c6f

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based device, the EFS partition can be erased. Apps processor then has non-secure world full read/write access to the partition until the modem boots and configures the EFS partition addresses in its MPU partition.

Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based device, the EFS partition can be erased. Apps processor then has non-secure world full read/write access to the partition until the modem boots and configures the EFS partition addresses in its MPU partition.

EPSS

Процентиль: 26%
0.0009
Низкий

7.7 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.7
nvd
больше 7 лет назад

Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based device, the EFS partition can be erased. Apps processor then has non-secure world full read/write access to the partition until the modem boots and configures the EFS partition addresses in its MPU partition.

EPSS

Процентиль: 26%
0.0009
Низкий

7.7 High

CVSS3

Дефекты

CWE-732