ZeroHour

CVE-2018-13913

CVSS 3.0
7.8 high
EPSS
<1%p12
Published
()
Modified
Description

Improper validation of array index can lead to unauthorized access while processing debugFS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in version MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 615/16/SD 415, SD 625, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24.

Vendors
qualcomm
Products
snapdragon auto firmware, snapdragon consumer internet of things firmware, snapdragon industrial internet of things firmware, snapdragon internet of things firmware, snapdragon mobile firmware, snapdragon voice \& music firmware, mdm9150 firmware, mdm9206 firmware, mdm9607 firmware, mdm9640 firmware, mdm9650 firmware, msm8909w firmware
Weakness
CWE-129
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.