First published: Mon Feb 04 2019(Updated: )
Improper input validation can lead RW access to secure subsystem from HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9650, MDM9655, MSM8996AU, QCS605, SD 410/12, SD 615/16/SD 415, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SXR1130.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Qualcomm Mdm9650 Firmware | ||
Qualcomm Mdm9650 | ||
Qualcomm Mdm9655 Firmware | ||
Qualcomm Mdm9655 | ||
Qualcomm Msm8996au Firmware | ||
Qualcomm Msm8996au | ||
Qualcomm Qcs605 Firmware | ||
Qualcomm Qcs605 | ||
Qualcomm Sd 410 Firmware | ||
Qualcomm Sd 410 | ||
Qualcomm Sd 12 Firmware | ||
Qualcomm Sd 12 | ||
Qualcomm Sd 615 Firmware | ||
Qualcomm Sd 615 | ||
Qualcomm Sd 16 Firmware | ||
Qualcomm Sd 16 | ||
Qualcomm Sd 415 Firmware | ||
Qualcomm Sd 415 | ||
Qualcomm Sd 675 Firmware | ||
Qualcomm Sd 675 | ||
Qualcomm Sd 712 Firmware | ||
Qualcomm Sd 712 | ||
Qualcomm Sd 710 Firmware | ||
Qualcomm Sd 710 | ||
Qualcomm Sd 670 Firmware | ||
Qualcomm Sd 670 | ||
Qualcomm Sd 820 Firmware | ||
Qualcomm Sd 820 | ||
Qualcomm Sd 820a Firmware | ||
Qualcomm Sd 820a | ||
Qualcomm Sd 835 Firmware | ||
Qualcomm Sd 835 | ||
Qualcomm Sd 845 Firmware | ||
Qualcomm Sd 845 | ||
Qualcomm Sd 850 Firmware | ||
Qualcomm Sd 850 | ||
Qualcomm Sd 8cx Firmware | ||
Qualcomm Sd 8cx | ||
Qualcomm Sxr1130 Firmware | ||
Qualcomm Sxr1130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-11932 is critical with a CVSS score of 9.1.
Qualcomm MDM9650 Firmware, Qualcomm MDM9655 Firmware, Qualcomm MSM8996AU Firmware, Qualcomm QCS605 Firmware, Qualcomm SD 410 Firmware, Google Android, Qualcomm SD 16 Firmware, Qualcomm SD 415 Firmware, Qualcomm SD 675 Firmware, Qualcomm SD 712 Firmware, Qualcomm SD 710 Firmware, Qualcomm SD 670 Firmware, Qualcomm SD 820a Firmware, Qualcomm SD 835 Firmware, Qualcomm SD 845 Firmware, Qualcomm SD 850 Firmware, Qualcomm SD 8cx Firmware, Qualcomm SXR1130 Firmware.
CVE-2018-11932 allows for improper input validation, which can lead to read and write access to the secure subsystem from the HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, and Snapdragon Mobile.
The fix for CVE-2018-11932 is to apply the appropriate security patches provided by the software vendor or upgrade to a non-vulnerable version of the software.
Yes, you can find additional references for CVE-2018-11932 at the following links: [Link 1](https://source.android.com/docs/security/bulletin/2019-02-01/#asterisk), [Link 2](https://source.android.com/docs/security/bulletin/2019-02-01), [Link 3](http://www.securityfocus.com/bid/106845).