CVE-2018-11845: Infoleak
Usage of non-time-constant comparison functions can lead to information leakage through side channel analysis in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in versions MDM9150, MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM439, SDM630, SDM660, SnapdragonHighMed2016, SXR1130.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11845?
CVE-2018-11845 has been assigned a medium severity rating due to its potential for information leakage through side channel analysis.
How do I fix CVE-2018-11845?
To mitigate CVE-2018-11845, it's essential to update affected Qualcomm firmware to the latest version provided by Qualcomm.
What type of devices are affected by CVE-2018-11845?
CVE-2018-11845 affects various Qualcomm products including Snapdragon and MDM firmware across multiple device categories.
Is CVE-2018-11845 exploitative in nature?
Yes, CVE-2018-11845 can be exploited to extract sensitive information through side channel attacks.
What is the nature of the vulnerability in CVE-2018-11845?
CVE-2018-11845 is caused by the usage of non-time-constant comparison functions, which can lead to information leakage.