CVE-2018-11291: Weak RNG
In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDM630, SDM632, SDM636, SDM660, SDX20, SnapdragonHighMed2016, cryptographic issues due to the random number generator was not a strong one in NAN.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11291?
CVE-2018-11291 is a vulnerability in Snapdragon (Automobile, Mobile, Wear) devices.
What is the severity of CVE-2018-11291?
The severity of CVE-2018-11291 is high with a CVSS score of 7.5.
Which devices are affected by CVE-2018-11291?
CVE-2018-11291 affects Snapdragon (Automobile, Mobile, Wear) devices including IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 650/52, SD 810, SD 820, SD 820A, and more.
What is the fix for CVE-2018-11291?
To fix CVE-2018-11291, users should apply the necessary firmware updates provided by Qualcomm or Google.
Where can I find more information about CVE-2018-11291?
You can find more information about CVE-2018-11291 on the Android Security Bulletin for April 2019 and the SecurityFocus website.