ID

VAR-201907-1112


CVE

CVE-2018-13897


TITLE

plural Snapdragon Information disclosure vulnerability in products

Trust: 0.8

sources: JVNDB: JVNDB-2018-015930

DESCRIPTION

Clients hostname gets added to DNS record on device which is running dnsmasq resulting in an information exposure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 625, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 855, SDA660, SDM630, SDM660. plural Snapdragon The product contains an information disclosure vulnerability.Information may be obtained. Qualcomm MDM9206 is a central processing unit (CPU) product of Qualcomm (Qualcomm). This vulnerability stems from configuration errors in network systems or products during operation. An unauthorized attacker could exploit the vulnerability to obtain sensitive information of the affected components. The following products and versions are affected: Qualcomm MDM9206; MDM9607; MDM9640; MDM9650; MSM8909W; MSM8996AU; QCS605; SD 210; SD 212; SD 205; SD 675; SD 712; SD 710; SD 670; SD 730; SD 820; SD 820A;

Trust: 1.8

sources: NVD: CVE-2018-13897 // JVNDB: JVNDB-2018-015930 // VULHUB: VHN-124002 // VULMON: CVE-2018-13897

AFFECTED PRODUCTS

vendor:qualcommmodel:msm8996auscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 415scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qcs605scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 205scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 212scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sda660scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 835scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 652scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 710scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 675scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 820ascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9607scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 730scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 615scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9206scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdm630scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdm660scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 820scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 616scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9640scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:msm8909wscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 670scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 855scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 210scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 712scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 636scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 625scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9206scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9607scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9640scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9650scope: - version: -

Trust: 0.8

vendor:qualcommmodel:msm8909wscope: - version: -

Trust: 0.8

vendor:qualcommmodel:msm8996auscope: - version: -

Trust: 0.8

vendor:qualcommmodel:qcs605scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 205scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 210scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 212scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2018-015930 // NVD: CVE-2018-13897

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-13897
value: HIGH

Trust: 1.0

NVD: CVE-2018-13897
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201907-1318
value: HIGH

Trust: 0.6

VULHUB: VHN-124002
value: MEDIUM

Trust: 0.1

VULMON: CVE-2018-13897
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-13897
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-124002
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-13897
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-124002 // VULMON: CVE-2018-13897 // JVNDB: JVNDB-2018-015930 // CNNVD: CNNVD-201907-1318 // NVD: CVE-2018-13897

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-124002 // JVNDB: JVNDB-2018-015930 // NVD: CVE-2018-13897

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201907-1318

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201907-1318

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-015930

PATCH

title:July 2019 Code Aurora Security Bulletinurl:https://www.codeaurora.org/security-bulletin/2019/07/01/july-2019-code-aurora-security-bulletin

Trust: 0.8

title:Multiple Qualcomm Product information disclosure vulnerability repair measuresurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=95466

Trust: 0.6

sources: JVNDB: JVNDB-2018-015930 // CNNVD: CNNVD-201907-1318

EXTERNAL IDS

db:NVDid:CVE-2018-13897

Trust: 2.6

db:JVNDBid:JVNDB-2018-015930

Trust: 0.8

db:CNNVDid:CNNVD-201907-1318

Trust: 0.7

db:VULHUBid:VHN-124002

Trust: 0.1

db:VULMONid:CVE-2018-13897

Trust: 0.1

sources: VULHUB: VHN-124002 // VULMON: CVE-2018-13897 // JVNDB: JVNDB-2018-015930 // CNNVD: CNNVD-201907-1318 // NVD: CVE-2018-13897

REFERENCES

url:https://www.codeaurora.org/security-bulletin/2019/07/01/july-2019-code-aurora-security-bulletin

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-13897

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-13897

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/200.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-124002 // VULMON: CVE-2018-13897 // JVNDB: JVNDB-2018-015930 // CNNVD: CNNVD-201907-1318 // NVD: CVE-2018-13897

CREDITS

CERT

Trust: 0.6

sources: CNNVD: CNNVD-201907-1318

SOURCES

db:VULHUBid:VHN-124002
db:VULMONid:CVE-2018-13897
db:JVNDBid:JVNDB-2018-015930
db:CNNVDid:CNNVD-201907-1318
db:NVDid:CVE-2018-13897

LAST UPDATE DATE

2024-11-23T22:48:21.526000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-124002date:2019-08-05T00:00:00
db:VULMONid:CVE-2018-13897date:2019-08-05T00:00:00
db:JVNDBid:JVNDB-2018-015930date:2019-08-06T00:00:00
db:CNNVDid:CNNVD-201907-1318date:2019-08-06T00:00:00
db:NVDid:CVE-2018-13897date:2024-11-21T03:48:16.307

SOURCES RELEASE DATE

db:VULHUBid:VHN-124002date:2019-07-25T00:00:00
db:VULMONid:CVE-2018-13897date:2019-07-25T00:00:00
db:JVNDBid:JVNDB-2018-015930date:2019-08-06T00:00:00
db:CNNVDid:CNNVD-201907-1318date:2019-07-25T00:00:00
db:NVDid:CVE-2018-13897date:2019-07-25T17:15:10.987