CVE-2017-13218 is a local information disclosure vulnerability affecting numerous Qualcomm Snapdragon products, including mobile, automotive, and IoT chipsets. It allows an attacker to perform side-channel attacks by accessing the CNTVCT_EL0 register, potentially leaking sensitive data without requiring elevated privileges. The vulnerability has a CVSS score of 4.7 (Medium), indicating a local attack vector with high attack complexity and high confidentiality impact. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, primarily in the context of Meltdown and Spectre-related advisories.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.