ID

VAR-201901-1327


CVE

CVE-2018-5881


TITLE

snapdragon mobile and snapdragon wear Buffer error vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-013778

DESCRIPTION

Improper validation of buffer length checks in the lwm2m device management protocol can leads to a buffer overflow in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 835, SDA660, SDM630, SDM660. snapdragon mobile and snapdragon wear Contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Qualcomm MDM9206, etc. are the central processing unit (CPU) products of Qualcomm (Qualcomm) applied to different platforms. A buffer error vulnerability exists in the lwm2m device management protocol in several Qualcomm snapdragon products. Currently there is no information about this vulnerability, please keep an eye on CNNVD or vendor announcements

Trust: 1.71

sources: NVD: CVE-2018-5881 // JVNDB: JVNDB-2018-013778 // VULHUB: VHN-135913

AFFECTED PRODUCTS

vendor:qualcommmodel:mdm9206scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdm630scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdm660scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 450scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 427scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 205scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 212scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 435scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sda660scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 835scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 425scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 210scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 430scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9607scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 636scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 625scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9206scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9607scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 205scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 210scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 212scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 425scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 427scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 430scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 435scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 450scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2018-013778 // NVD: CVE-2018-5881

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-5881
value: HIGH

Trust: 1.0

NVD: CVE-2018-5881
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201901-760
value: HIGH

Trust: 0.6

VULHUB: VHN-135913
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-5881
severity: HIGH
baseScore: 8.3
vectorString: AV:A/AC:L/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-135913
severity: HIGH
baseScore: 8.3
vectorString: AV:A/AC:L/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-5881
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-135913 // JVNDB: JVNDB-2018-013778 // CNNVD: CNNVD-201901-760 // NVD: CVE-2018-5881

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-135913 // JVNDB: JVNDB-2018-013778 // NVD: CVE-2018-5881

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-201901-760

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-201901-760

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-013778

PATCH

title:December 2018 Qualcomm Technologies, Inc. Security Bulletinurl:https://www.qualcomm.com/company/product-security/bulletins

Trust: 0.8

title:Multiple Qualcomm snapdragon Product Buffer Error Vulnerability Fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=88862

Trust: 0.6

sources: JVNDB: JVNDB-2018-013778 // CNNVD: CNNVD-201901-760

EXTERNAL IDS

db:NVDid:CVE-2018-5881

Trust: 2.5

db:JVNDBid:JVNDB-2018-013778

Trust: 0.8

db:CNNVDid:CNNVD-201901-760

Trust: 0.7

db:VULHUBid:VHN-135913

Trust: 0.1

sources: VULHUB: VHN-135913 // JVNDB: JVNDB-2018-013778 // CNNVD: CNNVD-201901-760 // NVD: CVE-2018-5881

REFERENCES

url:https://www.qualcomm.com/company/product-security/bulletins

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-5881

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-5881

Trust: 0.8

sources: VULHUB: VHN-135913 // JVNDB: JVNDB-2018-013778 // CNNVD: CNNVD-201901-760 // NVD: CVE-2018-5881

SOURCES

db:VULHUBid:VHN-135913
db:JVNDBid:JVNDB-2018-013778
db:CNNVDid:CNNVD-201901-760
db:NVDid:CVE-2018-5881

LAST UPDATE DATE

2024-11-23T22:12:10.543000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-135913date:2019-01-24T00:00:00
db:JVNDBid:JVNDB-2018-013778date:2019-03-01T00:00:00
db:CNNVDid:CNNVD-201901-760date:2019-04-01T00:00:00
db:NVDid:CVE-2018-5881date:2024-11-21T04:09:37.750

SOURCES RELEASE DATE

db:VULHUBid:VHN-135913date:2019-01-18T00:00:00
db:JVNDBid:JVNDB-2018-013778date:2019-03-01T00:00:00
db:CNNVDid:CNNVD-201901-760date:2019-01-21T00:00:00
db:NVDid:CVE-2018-5881date:2019-01-18T22:29:00.910