CVE-2018-13904 PUBLISHED CVSS 9.800000190734863 CRITICAL

Improper input validation in SCM handler to access storage in TZ can lead to unauthorized access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9206, MDM9607, MDM9650, MDM9655, QCS605, SD 410/12, SD 675, SD 712 / SD 710 / SD 670, SD 8CX, SXR1130.

EPSS 0.39% · 59.9th percentile

Risk Scores

CVSS v3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.39%
59.9th percentile

Affected Products

VendorProductVersions
qualcommsd_8cx_firmware
qualcommmdm9650_firmware
qualcommsd_710_firmware
qualcommsd_675_firmware
qualcommsd_712_firmware
qualcommsxr1130_firmware
qualcommmdm9607_firmware
qualcommsd_410_firmware
qualcommmdm9655_firmware
qualcommqcs605_firmware
qualcommsd_670_firmware
Qualcomm, Inc.Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon MobileMDM9206, MDM9607, MDM9650, MDM9655, QCS605, SD 410/12, SD 675, SD 712 / SD 710 / SD 670, SD 8CX, SXR1130
qualcommmdm9206_firmware
qualcommsd_12_firmware

Timeline

References

Open in Interactive Console →