CVE-2017-18126

EUVD-2017-9261
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9640, MDM9650, QCA6174A, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9379, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 835, SD 845, SDM630, SDM636, SDM660, Snapdragon_High_Med_2016, the original mac spoofing feature does not use the following in probe request frames: (a) randomized sequence numbers and (b) randomized source address for cfg80211 scan, vendor scan and pno scan which may affect user privacy.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
Affected Products (NVD)
VendorProductVersion
qualcommmdm9206_firmware
-
qualcommmdm9607_firmware
-
qualcommqca6174a_firmware
-
qualcommqca6574_firmware
-
qualcommmdm9640_firmware
-
qualcommqca6574au_firmware
-
qualcommmdm9650_firmware
-
qualcommqca6584_firmware
-
qualcommqca6584au_firmware
-
qualcommsd_210_firmware
-
qualcommsd_212_firmware
-
qualcommsd_205_firmware
-
qualcommqca9377_firmware
-
qualcommsd_410_firmware
-
qualcommsd_412_firmware
-
qualcommsd_425_firmware
-
qualcommsd_430_firmware
-
qualcommsd_450_firmware
-
qualcommsd_615_firmware
-
qualcommsd_616_firmware
-
qualcommsd_415_firmware
-
qualcommqca9379_firmware
-
qualcommsd_625_firmware
-
qualcommsd_650_firmware
-
qualcommsd_652_firmware
-
qualcommsd_427_firmware
-
qualcommsd_808_firmware
-
qualcommsd_810_firmware
-
qualcommsd_820_firmware
-
qualcommsd_835_firmware
-
qualcommsd_845_firmware
-
qualcommsd_435_firmware
-
qualcommsdm630_firmware
-
qualcommsdm636_firmware
-
qualcommsdm660_firmware
-
𝑥
= Vulnerable software versions