Lucene search

K
cveQualcommCVE-2018-11858
HistoryOct 29, 2018 - 6:29 p.m.

CVE-2018-11858

2018-10-2918:29:01
CWE-119
qualcomm
web.nvd.nist.gov
21
cve-2018-11858
snapdragon mobile
buffer overwrite
input validation
nvd
security vulnerability

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0

Percentile

12.6%

When processing IE set command, buffer overwrite may occur due to lack of input validation of the IE length in Snapdragon Mobile in version SD 835, SD 845, SD 850.

Affected configurations

Nvd
Node
qualcommsd_835Match-
AND
qualcommsd_835_firmwareMatch-
Node
qualcommsd_845Match-
AND
qualcommsd_845_firmwareMatch-
Node
qualcommsd_850Match-
AND
qualcommsd_850_firmwareMatch-
VendorProductVersionCPE
qualcommsd_835-cpe:2.3:h:qualcomm:sd_835:-:*:*:*:*:*:*:*
qualcommsd_835_firmware-cpe:2.3:o:qualcomm:sd_835_firmware:-:*:*:*:*:*:*:*
qualcommsd_845-cpe:2.3:h:qualcomm:sd_845:-:*:*:*:*:*:*:*
qualcommsd_845_firmware-cpe:2.3:o:qualcomm:sd_845_firmware:-:*:*:*:*:*:*:*
qualcommsd_850-cpe:2.3:h:qualcomm:sd_850:-:*:*:*:*:*:*:*
qualcommsd_850_firmware-cpe:2.3:o:qualcomm:sd_850_firmware:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Snapdragon Mobile",
    "vendor": "Qualcomm, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "SD 835, SD 845, SD 850"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2018-11858