Vulnerability Description
The TrustZone kernel, when used in conjunction with a certain Motorola build of Android 4.1.2, on Motorola Razr HD, Razr M, and Atrix HD devices with the Qualcomm MSM8960 chipset does not verify the association between a certain physical-address argument and a memory region, which allows local users to unlock the bootloader by using kernel mode to perform crafted 0x9 and 0x2 SMC operations, a different vulnerability than CVE-2013-2596.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Msm8960 | - |
| Motorola | Android | 4.1.2 |
| Motorola | Atrix Hd | - |
| Motorola | Razr Hd | - |
| Motorola | Razr M | - |
Related Weaknesses (CWE)
References
- http://blog.azimuthsecurity.com/2013/04/unlocking-motorola-bootloader.htmlExploit
- http://www.droid-life.com/2013/04/08/motorola-razr-hd-razr-m-and-atrix-hd-bootlo
- http://blog.azimuthsecurity.com/2013/04/unlocking-motorola-bootloader.htmlExploit
- http://www.droid-life.com/2013/04/08/motorola-razr-hd-razr-m-and-atrix-hd-bootlo
FAQ
What is CVE-2013-3051?
CVE-2013-3051 is a vulnerability with a CVSS score of 6.2 (MEDIUM). The TrustZone kernel, when used in conjunction with a certain Motorola build of Android 4.1.2, on Motorola Razr HD, Razr M, and Atrix HD devices with the Qualcomm MSM8960 chipset does not verify the a...
How severe is CVE-2013-3051?
CVE-2013-3051 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-3051?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Msm8960, Motorola Android, Motorola Atrix Hd, Motorola Razr Hd, Motorola Razr M.