CVE-2018-11820: Medium severity android vulnerability
Use of non-time constant memcmp function creates side channel that leaks information and leads to cryptographic issues in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in versions IPQ8074, MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MDM9655, MSM8996AU, QCA8081, QCS605, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 800, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM439, SDM630, SDM660, SnapdragonHighMed2016, SXR1130.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11820?
CVE-2018-11820 has been reported as a high-severity vulnerability due to its potential impact on cryptographic operations.
How do I fix CVE-2018-11820?
To mitigate CVE-2018-11820, update the affected Qualcomm firmware to a version that addresses the vulnerability.
Which products are affected by CVE-2018-11820?
CVE-2018-11820 affects several Qualcomm Snapdragon platforms including various firmware versions for Android and related devices.
What type of vulnerability is CVE-2018-11820?
CVE-2018-11820 is a cryptographic vulnerability related to the use of a non-time constant memcmp function, leading to potential information leaks.
Can CVE-2018-11820 be exploited remotely?
CVE-2018-11820 could potentially be exploited remotely if an attacker can access a vulnerable device or service.