CVE-2018-11849: Buffer Overflow
Lack of check on out of range of bssid parameter When processing scan start command will lead to buffer flow in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9886, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM630, SDM632, SDM636, SDM660, SDM710, SDX20, SnapdragonHighMed2016
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11849?
CVE-2018-11849 has a critical severity level due to the potential for buffer overflow vulnerabilities that could lead to remote code execution.
How do I fix CVE-2018-11849?
To mitigate CVE-2018-11849, users should update their affected Qualcomm devices with the latest firmware that addresses this vulnerability.
Which devices are affected by CVE-2018-11849?
CVE-2018-11849 affects various Qualcomm Snapdragon platforms, including IPQ8074, MDM9206, MDM9607, and many more mobile and automobile devices.
What type of vulnerability is CVE-2018-11849?
CVE-2018-11849 is characterized as a buffer overflow vulnerability due to lack of checks on the BSSID parameter.
Can CVE-2018-11849 lead to system exploitation?
Yes, exploitation of CVE-2018-11849 could allow an attacker to execute arbitrary code on affected systems.