CVE-2017-18057 is a high-severity vulnerability affecting Android devices utilizing the Linux kernel from CAF, specifically impacting the wma_nlo_scan_cmp_evt_handler() function. It stems from improper input validation of a vdev ID received from firmware, leading to a potential out-of-bounds memory read. The vulnerability has a CVSS score of 7.5, indicating a high risk, and can be exploited remotely without user interaction, potentially resulting in a complete compromise of confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.