First published: Fri Jun 14 2019(Updated: )
Use after issue in WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, QCA6574AU, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SDX20
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm MDM9150 firmware | ||
Qualcomm MDM9150 firmware | ||
Qualcomm MDM9206 | ||
Qualcomm MDM9206 firmware | ||
Qualcomm MD9607 Firmware | ||
Qualcomm MDM9607 firmware | ||
qualcomm mdm9640 firmware | ||
Qualcomm MDM9640 | ||
Qualcomm MDM9650 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm MSM8909W | ||
Qualcomm Snapdragon 8909 | ||
Qualcomm QCA6574 Firmware | ||
Qualcomm QCA6574AU | ||
Qualcomm SD210 Firmware | ||
Qualcomm SD 210 Firmware | ||
Qualcomm SD 212 | ||
Qualcomm SD 212 Firmware | ||
Qualcomm SD205 Firmware | ||
Qualcomm SD205 Firmware | ||
Qualcomm SD615 Firmware | ||
Qualcomm Snapdragon 615 | ||
Qualcomm SD 616 Firmware | ||
Qualcomm Snapdragon 616 | ||
Qualcomm Snapdragon 415 Firmware | ||
Qualcomm Snapdragon 415 | ||
Qualcomm SD 625 Firmware | ||
Qualcomm Snapdragon 625 | ||
Qualcomm SD650 Firmware | ||
Qualcomm Snapdragon 650 | ||
Qualcomm SD652 Firmware | ||
Qualcomm SD652 Firmware | ||
Qualcomm SD820 Firmware | ||
Qualcomm SD820 Firmware | ||
Qualcomm SDX20 Firmware | ||
Qualcomm SDX20 Firmware |
https://www.codeaurora.org/security-bulletin/2019/05/06/may-2019-code-aurora-security-bulletin
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11939 is a vulnerability that allows for a use after issue in the WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, QCA6574AU, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 625, SD 650/52, SD 820/SD 820A, Snapdragon Heterogeneous Compute, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ4019, MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, QCA6574AU, QCM2150, Qualcomm 215, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 625, SD 650/52, SD 820/SD 820A, SDX20, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearable and Snapdragon Wired Infrastructure and Networking in IPQ4019, MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, QCA6574AU, QCM2150, Qualcomm 215, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 625, SD 650/52, SD 820/SD 820A and SDX20.
The severity of CVE-2018-11939 is high with a CVSS score of 7.8.
The software affected by CVE-2018-11939 includes Qualcomm Mdm9150 Firmware, Qualcomm Mdm9206 Firmware, Qualcomm Mdm9607 Firmware, Qualcomm Mdm9640 Firmware, Qualcomm Mdm9650 Firmware, Qualcomm Msm8909w, Qualcomm Qca6574au, Qualcomm Sd 210 Firmware, Qualcomm Sd 212 Firmware, Qualcomm Sd 205 Firmware, Qualcomm Sd 615 Firmware, Qualcomm Sd 616 Firmware, Qualcomm Sd 415 Firmware, Qualcomm Sd 625 Firmware, Qualcomm Sd 650 Firmware, Qualcomm Sd 652 Firmware, Qualcomm Sd 820 Firmware, Qualcomm Sdx20 in various versions.
To fix CVE-2018-11939, it is recommended to apply the patches provided by Qualcomm if available, and follow their security recommendations.
More information about CVE-2018-11939 can be found on the Code Aurora Forum website at https://www.codeaurora.org/security-bulletin/2019/05/06/may-2019-code-aurora-security-bulletin.