ID

VAR-201904-0593


CVE

CVE-2018-11830


TITLE

plural Snapdragon Vulnerability related to input validation in products

Trust: 0.8

sources: JVNDB: JVNDB-2018-015206

DESCRIPTION

Improper input validation in QCPE create function may lead to integer overflow in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, SD 410/12, SD 820A. plural Snapdragon The product contains an input validation vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Qualcomm MDM9206 is a central processing unit (CPU) product of Qualcomm (Qualcomm). The QCPE creation function in several Qualcomm products has an input validation error vulnerability, which originates from the failure of the network system or product to properly validate the input data. The following products are affected: Qualcomm MDM9206; MDM9607; MDM9650; MDM9655; MSM8996AU; SD 410/12; SD 820A

Trust: 1.71

sources: NVD: CVE-2018-11830 // JVNDB: JVNDB-2018-015206 // VULHUB: VHN-121729

AFFECTED PRODUCTS

vendor:qualcommmodel:mdm9206scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 412scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 820ascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:msm8996auscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9655scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9607scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 410scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9206scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9607scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9650scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9655scope: - version: -

Trust: 0.8

vendor:qualcommmodel:msm8996auscope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 410scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 412scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 820ascope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2018-015206 // NVD: CVE-2018-11830

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-11830
value: HIGH

Trust: 1.0

NVD: CVE-2018-11830
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201904-212
value: HIGH

Trust: 0.6

VULHUB: VHN-121729
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-11830
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-121729
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-11830
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-121729 // JVNDB: JVNDB-2018-015206 // CNNVD: CNNVD-201904-212 // NVD: CVE-2018-11830

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-121729 // JVNDB: JVNDB-2018-015206 // NVD: CVE-2018-11830

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201904-212

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-201904-212

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-015206

PATCH

title:March 2019 Qualcomm Technologies, Inc. Security Bulletinurl:https://www.qualcomm.com/company/product-security/bulletins

Trust: 0.8

title:Multiple Qualcomm Product input verification error vulnerability fixesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=91092

Trust: 0.6

sources: JVNDB: JVNDB-2018-015206 // CNNVD: CNNVD-201904-212

EXTERNAL IDS

db:NVDid:CVE-2018-11830

Trust: 2.5

db:JVNDBid:JVNDB-2018-015206

Trust: 0.8

db:CNNVDid:CNNVD-201904-212

Trust: 0.7

db:VULHUBid:VHN-121729

Trust: 0.1

sources: VULHUB: VHN-121729 // JVNDB: JVNDB-2018-015206 // CNNVD: CNNVD-201904-212 // NVD: CVE-2018-11830

REFERENCES

url:https://www.qualcomm.com/company/product-security/bulletins

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2018-11830

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-11830

Trust: 0.8

sources: VULHUB: VHN-121729 // JVNDB: JVNDB-2018-015206 // CNNVD: CNNVD-201904-212 // NVD: CVE-2018-11830

SOURCES

db:VULHUBid:VHN-121729
db:JVNDBid:JVNDB-2018-015206
db:CNNVDid:CNNVD-201904-212
db:NVDid:CVE-2018-11830

LAST UPDATE DATE

2024-11-23T22:30:03.442000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-121729date:2019-04-07T00:00:00
db:JVNDBid:JVNDB-2018-015206date:2019-05-13T00:00:00
db:CNNVDid:CNNVD-201904-212date:2019-04-08T00:00:00
db:NVDid:CVE-2018-11830date:2024-11-21T03:44:06.210

SOURCES RELEASE DATE

db:VULHUBid:VHN-121729date:2019-04-04T00:00:00
db:JVNDBid:JVNDB-2018-015206date:2019-05-13T00:00:00
db:CNNVDid:CNNVD-201904-212date:2019-04-04T00:00:00
db:NVDid:CVE-2018-11830date:2019-04-04T15:29:00.453