First published: Tue Sep 04 2018(Updated: )
The use of a non-time-constant memory comparison operation can lead to timing/side channel attacks in Snapdragon Mobile in version SD 210/SD 212/SD 205, SD 845, SD 850
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm SD210 Firmware | ||
Qualcomm SD 210 Firmware | ||
Qualcomm SD 212 | ||
Qualcomm SD 212 Firmware | ||
Qualcomm 205 Firmware | ||
Qualcomm SD205 Firmware | ||
Qualcomm SDA845 Firmware | ||
Qualcomm SD845 | ||
Qualcomm SD850 Firmware | ||
Qualcomm SD850 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11846 has a high severity rating due to potential exposure to timing and side channel attacks.
Fixing CVE-2018-11846 involves updating the firmware to a version that uses time-constant memory comparison operations.
CVE-2018-11846 affects Qualcomm Snapdragon Mobile versions including SD 210, SD 212, SD 205, SD 845, and SD 850.
The consequences of CVE-2018-11846 can include unauthorized access to sensitive information through timing attacks.
As of now, there is no known public exploit for CVE-2018-11846, but the vulnerability itself poses significant risks.