CVE-2018-13900 PUBLISHED CVSS 7.800000190734863 HIGH

Use-after-free vulnerability will occur as there is no protection for the route table`s rule in IPA driver in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in versions MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24.

EPSS 0.05% · 15.8th percentile

Risk Scores

CVSS v3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.05%
15.8th percentile

Affected Products

VendorProductVersions
qualcommsd_710_firmware
qualcommsdm439_firmware
qualcommmsm8909w_firmware
qualcommsda660_firmware
qualcommsd_835_firmware
qualcommsd_820a_firmware
qualcommmdm9206_firmware
qualcommsd_712_firmware
qualcommsd_429_firmware
qualcommmdm9640_firmware
Qualcomm, Inc.Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon WearablesMDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24
qualcommsd_625_firmware
qualcommqcs605_firmware
qualcommsdm630_firmware
qualcommsd_850_firmware
qualcommmdm9607_firmware
qualcommsd_430_firmware
qualcommsd_425_firmware
qualcommsd_212_firmware
qualcommsd_670_firmware

…and 16 more

Timeline

References

Open in Interactive Console →