ZeroHour

CVE-2018-11899

CVSS 3.0
7.8 high
EPSS
<1%p9
Published
()
Modified
Description

While processing radio connection status change events, Radio index is not properly validated in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile and Snapdragon Voice & Music in versions MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24.

Vendors
qualcomm
Products
mdm9206 firmware, mdm9607 firmware, mdm9640 firmware, mdm9650 firmware, msm8996au firmware, sd 210 firmware, sd 212 firmware, sd 205 firmware, sd 425 firmware, sd 427 firmware, sd 430 firmware, sd 435 firmware
Weakness
CWE-129
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.