ID

VAR-201902-0535


CVE

CVE-2018-11888


TITLE

plural Snapdragon Vulnerabilities related to authorization, authority, and access control in products

Trust: 0.8

sources: JVNDB: JVNDB-2018-013675

DESCRIPTION

Unauthorized access may be allowed by the SCP11 Crypto Services TA will processing commands from other TA in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile and Snapdragon Voice & Music in versions MDM9607, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 650/52, SD 820, SD 820A, SD 835, SD 8CX, SDM439, Snapdragon_High_Med_2016. plural Snapdragon The product contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Qualcomm Closed-Source Components are prone to multiple unspecified vulnerabilities. An attacker can exploit these issues to perform unauthorized actions. This may aid in further attacks. These issues are being tracked by Android Bug IDs A-111092812, A-111093241 and A-117119136. Qualcomm MDM9607, etc. are the central processing unit (CPU) products of Qualcomm (Qualcomm) for different platforms. Cyrpto Services is one of the encryption service components. Permission and access control vulnerabilities exist in Cyrpto Services in several Qualcomm products. The following products are affected: Qualcomm MDM9607; MDM9650; MDM9655; MSM8996AU; SD 210; SD 212; SD 205; SD 615/16; SD 415; SD 625; SD 632; SD 650/52; SD 820; SD 820A; SD 835; SD 8CX; SDM439; Snapdragon_High_Med_2016

Trust: 2.07

sources: NVD: CVE-2018-11888 // JVNDB: JVNDB-2018-013675 // BID: 106475 // VULHUB: VHN-121792 // VULMON: CVE-2018-11888

AFFECTED PRODUCTS

vendor:qualcommmodel:sd 430scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdm439scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 412scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 439scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 210scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9655scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 820ascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 8cxscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 205scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 615scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 410scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 429scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 450scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 415scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 632scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 616scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9607scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 625scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 652scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:msm8996auscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:snapdragon high med 2016scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 427scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 435scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 820scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 425scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 212scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 835scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9607scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9650scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9655scope: - version: -

Trust: 0.8

vendor:qualcommmodel:msm8996auscope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 205scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 210scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 212scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 410scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 412scope: - version: -

Trust: 0.8

vendor:googlemodel:pixel xlscope:eqversion:0

Trust: 0.3

vendor:googlemodel:pixel cscope:eqversion:0

Trust: 0.3

vendor:googlemodel:pixelscope:eqversion:0

Trust: 0.3

vendor:googlemodel:nexus playerscope:eqversion:0

Trust: 0.3

vendor:googlemodel:nexusscope:eqversion:9

Trust: 0.3

vendor:googlemodel:nexus 6pscope: - version: -

Trust: 0.3

vendor:googlemodel:nexusscope:eqversion:6

Trust: 0.3

vendor:googlemodel:nexusscope:eqversion:5x

Trust: 0.3

vendor:googlemodel:androidscope:eqversion:0

Trust: 0.3

sources: BID: 106475 // JVNDB: JVNDB-2018-013675 // NVD: CVE-2018-11888

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-11888
value: HIGH

Trust: 1.0

NVD: CVE-2018-11888
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201901-182
value: HIGH

Trust: 0.6

VULHUB: VHN-121792
value: HIGH

Trust: 0.1

VULMON: CVE-2018-11888
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-11888
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-121792
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-11888
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-121792 // VULMON: CVE-2018-11888 // JVNDB: JVNDB-2018-013675 // CNNVD: CNNVD-201901-182 // NVD: CVE-2018-11888

PROBLEMTYPE DATA

problemtype:CWE-862

Trust: 1.1

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-121792 // JVNDB: JVNDB-2018-013675 // NVD: CVE-2018-11888

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201901-182

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201901-182

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-013675

PATCH

title:January 2019 Qualcomm Technologies, Inc. Security Bulletinurl:https://www.qualcomm.com/company/product-security/bulletins

Trust: 0.8

title:Multiple Qualcomm product Cyrpto Services Fixes for permission permissions and access control vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=88369

Trust: 0.6

title:Android Security Bulletins: Android Security Bulletin—January 2019url:https://vulmon.com/vendoradvisory?qidtp=android_security_bulletins&qid=6f7705599658e12e11baf07588cec356

Trust: 0.1

sources: VULMON: CVE-2018-11888 // JVNDB: JVNDB-2018-013675 // CNNVD: CNNVD-201901-182

EXTERNAL IDS

db:NVDid:CVE-2018-11888

Trust: 2.9

db:BIDid:106475

Trust: 2.1

db:JVNDBid:JVNDB-2018-013675

Trust: 0.8

db:CNNVDid:CNNVD-201901-182

Trust: 0.7

db:VULHUBid:VHN-121792

Trust: 0.1

db:VULMONid:CVE-2018-11888

Trust: 0.1

sources: VULHUB: VHN-121792 // VULMON: CVE-2018-11888 // BID: 106475 // JVNDB: JVNDB-2018-013675 // CNNVD: CNNVD-201901-182 // NVD: CVE-2018-11888

REFERENCES

url:http://www.securityfocus.com/bid/106475

Trust: 2.4

url:https://www.qualcomm.com/company/product-security/bulletins

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-11888

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-11888

Trust: 0.8

url:https://source.android.com/security/bulletin/2019-01-01

Trust: 0.6

url:https://source.android.com/security/bulletin/2019-01-01.html

Trust: 0.4

url:http://code.google.com/android/

Trust: 0.3

url:http://www.qualcomm.com/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/862.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-121792 // VULMON: CVE-2018-11888 // BID: 106475 // JVNDB: JVNDB-2018-013675 // CNNVD: CNNVD-201901-182 // NVD: CVE-2018-11888

CREDITS

The vendor reported these issues.

Trust: 0.3

sources: BID: 106475

SOURCES

db:VULHUBid:VHN-121792
db:VULMONid:CVE-2018-11888
db:BIDid:106475
db:JVNDBid:JVNDB-2018-013675
db:CNNVDid:CNNVD-201901-182
db:NVDid:CVE-2018-11888

LAST UPDATE DATE

2024-08-14T14:04:36.711000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-121792date:2019-10-03T00:00:00
db:VULMONid:CVE-2018-11888date:2019-10-03T00:00:00
db:BIDid:106475date:2019-01-07T00:00:00
db:JVNDBid:JVNDB-2018-013675date:2019-02-28T00:00:00
db:CNNVDid:CNNVD-201901-182date:2020-01-08T00:00:00
db:NVDid:CVE-2018-11888date:2019-10-03T00:03:26.223

SOURCES RELEASE DATE

db:VULHUBid:VHN-121792date:2019-02-11T00:00:00
db:VULMONid:CVE-2018-11888date:2019-02-11T00:00:00
db:BIDid:106475date:2019-01-07T00:00:00
db:JVNDBid:JVNDB-2018-013675date:2019-02-28T00:00:00
db:CNNVDid:CNNVD-201901-182date:2019-01-09T00:00:00
db:NVDid:CVE-2018-11888date:2019-02-11T15:29:00.363