CVE-2018-11945: Input Validation
Improper input validation in wireless service messaging module for data received from broadcast messages can lead to heap overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in versions MDM9150, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, SDX20, SnapdragonHighMed2016, SXR1130.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11945?
CVE-2018-11945 has a high severity due to the potential for heap overflow leading to serious exploits in affected devices.
How do I fix CVE-2018-11945?
To fix CVE-2018-11945, ensure your device firmware is updated to the latest version provided by Qualcomm or your device manufacturer.
Which devices are affected by CVE-2018-11945?
CVE-2018-11945 affects various Qualcomm Snapdragon platforms including MDM9150, MDM9206, MDM9607, and others.
What type of vulnerability is CVE-2018-11945?
CVE-2018-11945 is classified as an improper input validation vulnerability that can lead to heap overflow.
Can CVE-2018-11945 be exploited remotely?
Yes, CVE-2018-11945 can potentially be exploited remotely through malicious broadcast messages.