CVE-2018-11932
Last modified
CVE-2018-11932 is a vulnerability of currently unknown severity. Improper input validation can lead RW access to secure subsystem from HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9650, MDM9655, MSM8996AU, QCS605, SD 410/12, SD 615/16/SD 415, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SXR1130.. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
Improper input validation can lead RW access to secure subsystem from HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9650, MDM9655, MSM8996AU, QCS605, SD 410/12, SD 615/16/SD 415, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SXR1130.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Mdm9650 Firmware | All versions |
| Qualcomm | Mdm9655 Firmware | All versions |
| Qualcomm | Msm8996au Firmware | All versions |
| Qualcomm | Qcs605 Firmware | All versions |
| Qualcomm | Sd 410 Firmware | All versions |
| Qualcomm | Sd 12 Firmware | All versions |
| Qualcomm | Sd 615 Firmware | All versions |
| Qualcomm | Sd 16 Firmware | All versions |
| Qualcomm | Sd 415 Firmware | All versions |
| Qualcomm | Sd 675 Firmware | All versions |
| Qualcomm | Sd 712 Firmware | All versions |
| Qualcomm | Sd 710 Firmware | All versions |
| Qualcomm | Sd 670 Firmware | All versions |
| Qualcomm | Sd 820 Firmware | All versions |
| Qualcomm | Sd 820a Firmware | All versions |
| Qualcomm | Sd 835 Firmware | All versions |
| Qualcomm | Sd 845 Firmware | All versions |
| Qualcomm | Sd 850 Firmware | All versions |
| Qualcomm | Sd 8cx Firmware | All versions |
| Qualcomm | Sxr1130 Firmware | All versions |
References
- http://www.securityfocus.com/bid/106845Third Party Advisory, VDB Entry
- https://www.qualcomm.com/company/product-security/bulletinsVendor Advisory
- http://www.securityfocus.com/bid/106845Third Party Advisory, VDB Entry
- https://www.qualcomm.com/company/product-security/bulletinsVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-11932?
How severe is CVE-2018-11932?
How do I fix CVE-2018-11932?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-11927Improper input validation on input which is used as an array…
- CVE-2018-11928Lack of check on length parameter may cause buffer overflow …
- CVE-2018-11929Lack of input validation in WLAN function can lead to potent…
- CVE-2018-1193Cloud Foundry routing-release, versions prior to 0.175.0, la…
- CVE-2018-11930Improper input validation on input data which is used to loc…
- CVE-2018-11931Improper access to HLOS is possible while transferring memor…
- CVE-2018-11933Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-11934Possible out of bounds write due to improper input validatio…
- CVE-2018-11935Improper input validation might result in incorrect app id r…
- CVE-2018-11936Index of array is processed in a wrong way inside a while lo…
- CVE-2018-11937Lack of input validation before copying can lead to a buffer…
- CVE-2018-11938Improper input validation for argument received from HLOS ca…
Are you affected by CVE-2018-11932?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
