Lucene search

K
cveQualcommCVE-2018-11854
HistoryOct 26, 2018 - 1:29 p.m.

CVE-2018-11854

2018-10-2613:29:01
CWE-119
qualcomm
web.nvd.nist.gov
22
wlan
snapdragon
mobile
cve-2018-11854
buffer overwrite
input parameter length
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0

Percentile

12.6%

Lack of check of valid length of input parameter may cause buffer overwrite in WLAN in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660

Affected configurations

Nvd
Node
qualcommsd_835Match-
AND
qualcommsd_835_firmwareMatch-
Node
qualcommsd_845Match-
AND
qualcommsd_845_firmwareMatch-
Node
qualcommsd_850Match-
AND
qualcommsd_850_firmwareMatch-
Node
qualcommsda660Match-
AND
qualcommsda660_firmwareMatch-
VendorProductVersionCPE
qualcommsd_835-cpe:2.3:h:qualcomm:sd_835:-:*:*:*:*:*:*:*
qualcommsd_835_firmware-cpe:2.3:o:qualcomm:sd_835_firmware:-:*:*:*:*:*:*:*
qualcommsd_845-cpe:2.3:h:qualcomm:sd_845:-:*:*:*:*:*:*:*
qualcommsd_845_firmware-cpe:2.3:o:qualcomm:sd_845_firmware:-:*:*:*:*:*:*:*
qualcommsd_850-cpe:2.3:h:qualcomm:sd_850:-:*:*:*:*:*:*:*
qualcommsd_850_firmware-cpe:2.3:o:qualcomm:sd_850_firmware:-:*:*:*:*:*:*:*
qualcommsda660-cpe:2.3:h:qualcomm:sda660:-:*:*:*:*:*:*:*
qualcommsda660_firmware-cpe:2.3:o:qualcomm:sda660_firmware:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Snapdragon Mobile",
    "vendor": "Qualcomm, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "SD 835, SD 845, SD 850, SDA660"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2018-11854