ZeroHour

CVE-2018-5839

CVSS 3.0
7.1 high
EPSS
<1%p11
Published
()
Modified
Description

Improperly configured memory protection allows read/write access to modem image from HLOS kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9150, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8996AU, QCS605, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SDX20, SXR1130.

Vendors
qualcomm
Products
snapdragon auto firmware, snapdragon compute firmware, snapdragon consumer internet of things firmware, snapdragon industrial internet of things firmware, mdm9150 firmware, mdm9615 firmware, mdm9625 firmware, mdm9635m firmware, mdm9640 firmware, mdm9650 firmware, mdm9655 firmware, msm8996au firmware
Weakness
CWE-269
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.