First published: Tue Sep 04 2018(Updated: )
If an end user makes use of SCP11 sample OCE code without modification it could lead to a buffer overflow when transmitting a CAPDU in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT and Snapdragon Mobile in versions MDM9607, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 636, SD 820, SD 820A, SD 835, SD 8CX, SDA660, SDM630, SDM660.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm MDM9607 firmware | ||
Qualcomm MDM9607 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm MDM9650 | ||
Qualcomm MDM9655 firmware | ||
Qualcomm MDM9655 | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm MSM8996AU Firmware | ||
qualcomm SD 210 firmware | ||
qualcomm SD 210 | ||
qualcomm SD 212 firmware | ||
qualcomm SD 212 | ||
qualcomm SD 205 firmware | ||
qualcomm SD 205 | ||
qualcomm sd 410 firmware | ||
qualcomm sd 410 | ||
qualcomm sd 412 firmware | ||
qualcomm sd 412 | ||
qualcomm SD 636 firmware | ||
qualcomm SD 636 | ||
qualcomm SD 820 firmware | ||
qualcomm SD 820 | ||
qualcomm SD 820A firmware | ||
qualcomm SD 820A | ||
qualcomm SD 835 firmware | ||
qualcomm SD 835 | ||
qualcomm SD 8CX firmware | ||
qualcomm SD 8CX | ||
qualcomm SDA660 firmware | ||
qualcomm SDA660 | ||
qualcomm SDM630 firmware | ||
qualcomm SDM630 | ||
qualcomm SDM660 firmware | ||
qualcomm SDM660 | ||
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11855 is rated as high severity due to the potential for a buffer overflow.
To remediate CVE-2018-11855, users should ensure they do not use the unmodified SCP11 sample OCE code.
CVE-2018-11855 affects various Qualcomm Snapdragon platforms, including MDM9607, MDM9650, and others.
Yes, CVE-2018-11855 could potentially allow an attacker to execute arbitrary code remotely due to the buffer overflow.
While CVE-2018-11855 is associated with Android devices, it primarily affects Qualcomm hardware and firmware implementations.