ID

VAR-201904-0543


CVE

CVE-2018-11971


TITLE

plural Snapdragon Information disclosure vulnerability in products

Trust: 0.8

sources: JVNDB: JVNDB-2018-015200

DESCRIPTION

Interrupt exit code flow may undermine access control policy set forth by secure world can lead to potential secure asset leakage in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, in MDM9206, MDM9607, MDM9650, MDM9655, QCS605, SD 410/12, SD 615/16/SD 415, SD 636, SD 712 / SD 710 / SD 670, SD 845 / SD 850, SD 8CX, SDA660, SDM630, SDM660, SXR1130. plural Snapdragon The product contains an information disclosure vulnerability.Information may be obtained. QualcommMDM9607 and others are a central processing unit (CPU) product of Qualcomm. There are information disclosure vulnerabilities in TrustZone in several Qualcomm products. An attacker could exploit the vulnerability to disclose information. The following products are affected: Qualcomm MDM9206; MDM9607; MDM9650; MDM9655; QCS605; SD 410/12; SD 615/16; SD 415; SD 636; SD 712; SD 710; SDA660; SDM630; SDM660; SXR1130

Trust: 2.34

sources: NVD: CVE-2018-11971 // JVNDB: JVNDB-2018-015200 // CNVD: CNVD-2019-08980 // VULHUB: VHN-121884 // VULMON: CVE-2018-11971

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-08980

AFFECTED PRODUCTS

vendor:qualcommmodel:mdm9206scope: - version: -

Trust: 1.4

vendor:qualcommmodel:mdm9607scope: - version: -

Trust: 1.4

vendor:qualcommmodel:mdm9650scope: - version: -

Trust: 1.4

vendor:qualcommmodel:mdm9655scope: - version: -

Trust: 1.4

vendor:qualcommmodel:qcs605scope: - version: -

Trust: 1.4

vendor:qualcommmodel:sd 8cxscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 410scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 415scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qcs605scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sda660scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 710scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9607scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 850scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9206scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 615scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdm630scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 845scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdm660scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9655scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 616scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 670scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sxr1130scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 412scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 712scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 636scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 410scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 412scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 415scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 615scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 616scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sdscope:eqversion:850

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:615/16

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:415

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:410/12

Trust: 0.6

vendor:qualcommmodel:sdm630scope: - version: -

Trust: 0.6

vendor:qualcommmodel:sdm660scope: - version: -

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:845

Trust: 0.6

vendor:qualcommmodel:sda660scope: - version: -

Trust: 0.6

vendor:qualcommmodel:sxr1130scope: - version: -

Trust: 0.6

vendor:qualcommmodel:sd 8cxscope: - version: -

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:636

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:712

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:710

Trust: 0.6

vendor:qualcommmodel:sdscope:eqversion:670

Trust: 0.6

sources: CNVD: CNVD-2019-08980 // JVNDB: JVNDB-2018-015200 // NVD: CVE-2018-11971

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-11971
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-11971
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2019-08980
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201903-129
value: MEDIUM

Trust: 0.6

VULHUB: VHN-121884
value: MEDIUM

Trust: 0.1

VULMON: CVE-2018-11971
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-11971
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:C/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2019-08980
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-121884
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:C/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-11971
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2019-08980 // VULHUB: VHN-121884 // VULMON: CVE-2018-11971 // JVNDB: JVNDB-2018-015200 // CNNVD: CNNVD-201903-129 // NVD: CVE-2018-11971

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-121884 // JVNDB: JVNDB-2018-015200 // NVD: CVE-2018-11971

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201903-129

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201903-129

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-015200

PATCH

title:March 2019 Qualcomm Technologies, Inc. Security Bulletinurl:https://www.qualcomm.com/company/product-security/bulletins

Trust: 0.8

title:Patches for multiple Qualcomm Product Information Disclosure Vulnerabilities (CNVD-2019-08980)url:https://www.cnvd.org.cn/patchInfo/show/158075

Trust: 0.6

title:Multiple Qualcomm Product information disclosure vulnerability repair measuresurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=89799

Trust: 0.6

title:Android Security Bulletins: Android Security Bulletin — March 2019url:https://vulmon.com/vendoradvisory?qidtp=android_security_bulletins&qid=e9cddeba5732c8294d7cd6c4b6f1170b

Trust: 0.1

sources: CNVD: CNVD-2019-08980 // VULMON: CVE-2018-11971 // JVNDB: JVNDB-2018-015200 // CNNVD: CNNVD-201903-129

EXTERNAL IDS

db:NVDid:CVE-2018-11971

Trust: 3.2

db:JVNDBid:JVNDB-2018-015200

Trust: 0.8

db:CNNVDid:CNNVD-201903-129

Trust: 0.7

db:CNVDid:CNVD-2019-08980

Trust: 0.6

db:VULHUBid:VHN-121884

Trust: 0.1

db:VULMONid:CVE-2018-11971

Trust: 0.1

sources: CNVD: CNVD-2019-08980 // VULHUB: VHN-121884 // VULMON: CVE-2018-11971 // JVNDB: JVNDB-2018-015200 // CNNVD: CNNVD-201903-129 // NVD: CVE-2018-11971

REFERENCES

url:https://www.qualcomm.com/company/product-security/bulletins

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-11971

Trust: 1.4

url:https://vigilance.fr/vulnerability/google-android-pixel-multiple-vulnerabilities-of-march-2019-28664

Trust: 1.2

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-11971

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/200.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://source.android.com/security/bulletin/2019-03-01.html

Trust: 0.1

sources: CNVD: CNVD-2019-08980 // VULHUB: VHN-121884 // VULMON: CVE-2018-11971 // JVNDB: JVNDB-2018-015200 // CNNVD: CNNVD-201903-129 // NVD: CVE-2018-11971

SOURCES

db:CNVDid:CNVD-2019-08980
db:VULHUBid:VHN-121884
db:VULMONid:CVE-2018-11971
db:JVNDBid:JVNDB-2018-015200
db:CNNVDid:CNNVD-201903-129
db:NVDid:CVE-2018-11971

LAST UPDATE DATE

2024-11-23T22:17:05.596000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-08980date:2019-04-03T00:00:00
db:VULHUBid:VHN-121884date:2019-04-07T00:00:00
db:VULMONid:CVE-2018-11971date:2019-04-07T00:00:00
db:JVNDBid:JVNDB-2018-015200date:2019-05-13T00:00:00
db:CNNVDid:CNNVD-201903-129date:2019-04-09T00:00:00
db:NVDid:CVE-2018-11971date:2024-11-21T03:44:21.307

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-08980date:2019-04-03T00:00:00
db:VULHUBid:VHN-121884date:2019-04-04T00:00:00
db:VULMONid:CVE-2018-11971date:2019-04-04T00:00:00
db:JVNDBid:JVNDB-2018-015200date:2019-05-13T00:00:00
db:CNNVDid:CNNVD-201903-129date:2019-03-05T00:00:00
db:NVDid:CVE-2018-11971date:2019-04-04T15:29:00.767