CVE-2016-10417 describes a Time-of-Check to Time-of-Use (TOCTOU) vulnerability within Qualcomm's Trusted Execution Environment (QTEE) due to improper access control. This flaw affects numerous Qualcomm Snapdragon platforms, including those in Automobile, Mobile, and Wear devices, running Android versions prior to the 2018-04-05 security patch level. With a CVSSv3 score of 8.1 (HIGH), this vulnerability is remotely exploitable with high complexity, potentially leading to complete compromise of confidentiality, integrity, and availability of affected systems. There is no public exploit code available, nor is it listed on the CISA KEV catalog, indicating it is not actively exploited in the wild. Community discussion is minimal, with only one mention found.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:ipq4019_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:mdm9625_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:mdm9635m_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.