CVE-2017-11035 describes a buffer overflow or information leak vulnerability affecting Android for MSM, Firefox OS for MSM, and QRD Android releases from CAF using the Linux kernel. This flaw, stemming from incorrect initialization of WEXT callbacks and insufficient buffer size checks in "sme_set_ft_ies" and "csr_roam_issue_ft_preauth_req" functions, could allow an attacker to gain elevated privileges or access sensitive information. With a CVSS score of 7.8 (High), it presents a significant risk, requiring local access but having high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.