ID

VAR-E-201707-0324


CVE

cve_id:CVE-2017-7936

Trust: 0.3

cve_id:CVE-2017-7932

Trust: 0.3

sources: BID: 99966

TITLE

Multiple i.MX Products Multiple Local Security Vulnerabilities

Trust: 0.3

sources: BID: 99966

DESCRIPTION

Multiple i.MX Products is prone to multiple local security vulnerabilities.
An attacker may exploit these issues to bypass certain security restrictions and perform unauthorized actions or execute arbitrary code within the context of the application. Failed exploit attempts will likely cause a denial-of-service condition.

Trust: 0.3

sources: BID: 99966

AFFECTED PRODUCTS

vendor:nxpmodel:semiconductors vybrid vf5xxscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors vybrid vf3xxscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors mifare ultralightscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors mifare reader componentsscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors mifare desfire ev1scope: - version: -

Trust: 0.3

vendor:nxpmodel:semiconductors mifare classicscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 7soloscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 7dualscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6ultralitescope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6ullscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6soloxscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6sololitescope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6soloscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6quadplusscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6quadscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6dualplusscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6duallitescope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6dualscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imxscope:eqversion:530

Trust: 0.3

vendor:nxpmodel:semiconductors imxscope:eqversion:500

Trust: 0.3

vendor:nxpmodel:semiconductors imxscope:eqversion:280

Trust: 0.3

sources: BID: 99966

EXPLOIT

To exploit some of these issues, an attacker must entice an unsuspecting victim into following a malicious URI or visiting a malicious website.

Trust: 0.3

sources: BID: 99966

PRICE

Free

Trust: 0.3

sources: BID: 99966

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 99966

CREDITS

Quarkslab.

Trust: 0.3

sources: BID: 99966

EXTERNAL IDS

db:ICS CERTid:ICSA-17-152-02

Trust: 0.3

db:NVDid:CVE-2017-7936

Trust: 0.3

db:NVDid:CVE-2017-7932

Trust: 0.3

db:BIDid:99966

Trust: 0.3

sources: BID: 99966

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-17-152-02

Trust: 0.3

url:http://www.nxp.com/

Trust: 0.3

sources: BID: 99966

SOURCES

db:BIDid:99966

LAST UPDATE DATE

2022-07-27T09:58:26.476000+00:00


SOURCES UPDATE DATE

db:BIDid:99966date:2017-07-26T00:00:00

SOURCES RELEASE DATE

db:BIDid:99966date:2017-07-26T00:00:00