CVE-2018-11855: Buffer Overflow
If an end user makes use of SCP11 sample OCE code without modification it could lead to a buffer overflow when transmitting a CAPDU in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT and Snapdragon Mobile in versions MDM9607, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 636, SD 820, SD 820A, SD 835, SD 8CX, SDA660, SDM630, SDM660.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11855?
CVE-2018-11855 is rated as high severity due to the potential for a buffer overflow.
How do I fix CVE-2018-11855?
To remediate CVE-2018-11855, users should ensure they do not use the unmodified SCP11 sample OCE code.
What devices are affected by CVE-2018-11855?
CVE-2018-11855 affects various Qualcomm Snapdragon platforms, including MDM9607, MDM9650, and others.
Could CVE-2018-11855 lead to remote code execution?
Yes, CVE-2018-11855 could potentially allow an attacker to execute arbitrary code remotely due to the buffer overflow.
Is CVE-2018-11855 specific to Android devices?
While CVE-2018-11855 is associated with Android devices, it primarily affects Qualcomm hardware and firmware implementations.