CVE-2018-5892
UnknownEPSS 0.85%
Last modified
CVE-2018-5892 is a vulnerability of currently unknown severity. The Touch Pal application can collect user behavior data without awareness by the user in Snapdragon Mobile and Snapdragon Wear.. EPSS estimates a 0.85% chance of exploitation in the next 30 days.
Description
The Touch Pal application can collect user behavior data without awareness by the user in Snapdragon Mobile and Snapdragon Wear.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Mdm9206 Firmware | All versions |
| Qualcomm | Mdm9607 Firmware | All versions |
| Qualcomm | Mdm9650 Firmware | All versions |
| Qualcomm | Msm8996au Firmware | All versions |
| Qualcomm | Sd 210 Firmware | All versions |
| Qualcomm | Sd 212 Firmware | All versions |
| Qualcomm | Sd 205 Firmware | All versions |
| Qualcomm | Sd 425 Firmware | All versions |
| Qualcomm | Sd 427 Firmware | All versions |
| Qualcomm | Sd 430 Firmware | All versions |
| Qualcomm | Sd 435 Firmware | All versions |
| Qualcomm | Sd 450 Firmware | All versions |
| Qualcomm | Sd 615 Firmware | All versions |
| Qualcomm | Sd 616 Firmware | All versions |
| Qualcomm | Sd 415 Firmware | All versions |
| Qualcomm | Sd 625 Firmware | All versions |
| Qualcomm | Sd 650 Firmware | All versions |
| Qualcomm | Sd 652 Firmware | All versions |
| Qualcomm | Sd 810 Firmware | All versions |
| Qualcomm | Sd 820 Firmware | All versions |
| Qualcomm | Sd 835 Firmware | All versions |
| Qualcomm | Sd 845 Firmware | All versions |
| Qualcomm | Sdm630 Firmware | All versions |
| Qualcomm | Sdm636 Firmware | All versions |
| Qualcomm | Sdm660 Firmware | All versions |
| Qualcomm | Sdm710 Firmware | All versions |
| Qualcomm | Snapdragon High Med 2016 Firmware | All versions |
References
- https://www.qualcomm.com/company/product-security/bulletinsVendor Advisory
- https://www.qualcomm.com/company/product-security/bulletinsVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5892?
The Touch Pal application can collect user behavior data without awareness by the user in Snapdragon Mobile and Snapdragon Wear.
How severe is CVE-2018-5892?
Severity scoring for CVE-2018-5892 is pending analysis. The EPSS model estimates a 0.85% probability of exploitation in the next 30 days.
How do I fix CVE-2018-5892?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2018-5892?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
