Product Security
Description of Security Ratings
Version: 1.2 Updated: September 25th 2017
Each vulnerability is associated with a security risk rating of Critical, High, Medium or Low. Following are brief descriptions of these ratings. Please note that there will be vulnerabilities that don't fit the descriptions provided in this document and will require a specific judgement call. In our sole discretion, we will make reasonable attempts to adhere to the following rating levels.
Critical
Remote code execution, remote permanent denial of service (inoperability), bypassing or disabling critical security measures.
Critical vulnerabilities may allow an attacker to gain control of the device remotely, typically by sending a malicious input that is received and processed by the device. A vulnerability that permits an attack that may cause a device to stop functioning also falls into this category. In this case, a vulnerable device normally cannot be recovered from a hardware reset or will require an engineering procedure for recovery. Vulnerabilities that allow bypassing or disabling of a critical security mechanism, either locally or remotely, are also covered by this category. Examples include full compromises of a secure execution environment and secure boot bypasses.
High
High vulnerabilities may allow an unprivileged attacker to escalate privileges from a local execution context, execute arbitrary code, gain unauthorized access to confidential device information, or escalate execution from one trusted block or security domain to a higher trusted block or security domain. This category includes vulnerabilities that provide access to confidential device information, including device secrets, security settings, user confidential data, or information maintained by foundational security components. High-severity vulnerabilities may also allow an attacker to compromise critical trust boundaries between security domains, potentially enabling broader system compromise. Additionally, this category includes vulnerabilities that may allow an attacker to remotely (without user assistance) cause a device to crash and/or reboot, resulting in a temporary denial-of-service condition. Examples of confidential device information include device A-key or SIM-lock information, contents of secure storage, DRM keys, GPS information, and sensitive information maintained by foundational security components.
Medium
Medium vulnerabilities may allow an attacker to achieve impacts similar to High-rated vulnerabilities, but typically require additional user interaction, elevated preconditions, or the chaining of another vulnerability to be successfully exploited. Examples include local privilege escalation vulnerabilities that require privileges beyond those of a standard user as a prerequisite. This category also includes vulnerabilities that permit unauthorized access to sensitive, but not security-critical, device configuration information or locally accessible information from the host, such as exact device or firmware versions, IMEI, phone numbers, or other non-security-critical information disclosures. While these vulnerabilities do not directly compromise security-critical assets, they may assist attackers in identifying device-specific weaknesses and facilitate the execution of more serious attacks when combined with other vulnerabilities.
Low
Low vulnerabilities are security vulnerabilities that do not directly cause harm to the user or the device. They include access to general information such as general device settings or device-specific details such as device manufacturer, model, or HLOS in use. Vulnerabilities that do not qualify for any of the above categories, but that may add to the overall impact of another vulnerability, also fall into this category. This category also includes Defense-in-Depth issues that do not have an attack vector at the time of issue discovery, but improved code can mitigate the attack if other defense measures are rendered ineffective.
Revision History
September 25th 2017
- Version 1.2 - Made minor changes to critical and high rating levels
