First published: Fri Jun 14 2019(Updated: )
Use after issue in WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, QCA6574AU, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SDX20
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Mdm9150 Firmware | ||
Qualcomm Mdm9150 | ||
Qualcomm Mdm9206 Firmware | ||
Qualcomm Mdm9206 | ||
Qualcomm Mdm9607 Firmware | ||
Qualcomm Mdm9607 | ||
Qualcomm Mdm9640 Firmware | ||
Qualcomm Mdm9640 | ||
Qualcomm Mdm9650 Firmware | ||
Qualcomm Mdm9650 | ||
Qualcomm Msm8909w Firmware | ||
Qualcomm Msm8909w | ||
Qualcomm Qca6574au Firmware | ||
Qualcomm Qca6574au | ||
Qualcomm Sd 210 Firmware | ||
Qualcomm Sd 210 | ||
Qualcomm Sd 212 Firmware | ||
Qualcomm Sd 212 | ||
Qualcomm Sd 205 Firmware | ||
Qualcomm Sd 205 | ||
Qualcomm Sd 615 Firmware | ||
Qualcomm Sd 615 | ||
Qualcomm Sd 616 Firmware | ||
Qualcomm Sd 616 | ||
Qualcomm Sd 415 Firmware | ||
Qualcomm Sd 415 | ||
Qualcomm Sd 625 Firmware | ||
Qualcomm Sd 625 | ||
Qualcomm Sd 650 Firmware | ||
Qualcomm Sd 650 | ||
Qualcomm Sd 652 Firmware | ||
Qualcomm Sd 652 | ||
Qualcomm Sd 820 Firmware | ||
Qualcomm Sd 820 | ||
Qualcomm Sdx20 Firmware | ||
Qualcomm Sdx20 |
https://www.codeaurora.org/security-bulletin/2019/05/06/may-2019-code-aurora-security-bulletin
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11939 is a vulnerability that allows for a use after issue in the WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, QCA6574AU, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 625, SD 650/52, SD 820/SD 820A, Snapdragon Heterogeneous Compute, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ4019, MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, QCA6574AU, QCM2150, Qualcomm 215, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 625, SD 650/52, SD 820/SD 820A, SDX20, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearable and Snapdragon Wired Infrastructure and Networking in IPQ4019, MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, QCA6574AU, QCM2150, Qualcomm 215, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 625, SD 650/52, SD 820/SD 820A and SDX20.
The severity of CVE-2018-11939 is high with a CVSS score of 7.8.
The software affected by CVE-2018-11939 includes Qualcomm Mdm9150 Firmware, Qualcomm Mdm9206 Firmware, Qualcomm Mdm9607 Firmware, Qualcomm Mdm9640 Firmware, Qualcomm Mdm9650 Firmware, Qualcomm Msm8909w, Qualcomm Qca6574au, Qualcomm Sd 210 Firmware, Qualcomm Sd 212 Firmware, Qualcomm Sd 205 Firmware, Qualcomm Sd 615 Firmware, Qualcomm Sd 616 Firmware, Qualcomm Sd 415 Firmware, Qualcomm Sd 625 Firmware, Qualcomm Sd 650 Firmware, Qualcomm Sd 652 Firmware, Qualcomm Sd 820 Firmware, Qualcomm Sdx20 in various versions.
To fix CVE-2018-11939, it is recommended to apply the patches provided by Qualcomm if available, and follow their security recommendations.
More information about CVE-2018-11939 can be found on the Code Aurora Forum website at https://www.codeaurora.org/security-bulletin/2019/05/06/may-2019-code-aurora-security-bulletin.