Improper Input Validation in Qualcomm Snapdragon Products
CVE-2018-5869
7.8HIGH
Key Information:
- Vendor
- Qualcomm
- Vendor
- CVE Published:
- 18 January 2019
Summary
The vulnerability arises due to improper input validation within the QTEE keymaster application, which can cause unauthorized access to memory locations. This flaw affects multiple Snapdragon mobile and wear devices, potentially leading to serious security implications. Users are advised to update their devices to the latest firmware to mitigate risks associated with this vulnerability.
Affected Version(s)
Snapdragon Mobile,Snapdragon Wear MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD 800, SD 810
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved