CVE-2015-9216 describes a critical vulnerability in Qualcomm Snapdragon Mobile and Wear platforms, affecting numerous chipsets including the SD 210/212/205, SD 400, SD 625, and SD 810, in Android versions before April 5, 2018. This flaw stems from improper handling of simultaneous interrupts within the USB module during USB RESET and EP COMPLETE operations. With a CVSS v3.0 score of 9.8 (Critical), it allows for unauthenticated remote exploitation (AV:N/AC:L/PR:N/UI:N) leading to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). Despite its high severity and significant community discussion (10 mentions), there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:mdm9625_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:mdm9635m_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:msm8909w_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.