CVE-2018-13896: High severity android vulnerability
XBLSEC image authentication and other crypto related validations are accessible to a compromised OEM XBL Loader due to missing lock at XBLSEC stage.. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, QCS404, QCS605, Qualcomm 215, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, SnapdragonHighMed2016, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13896?
CVE-2018-13896 has been rated as a critical vulnerability due to its potential exploitation by a compromised OEM XBL Loader.
How do I fix CVE-2018-13896?
To mitigate CVE-2018-13896, update the affected Qualcomm firmware or apply patches provided by Qualcomm or your device manufacturer.
Which devices are affected by CVE-2018-13896?
CVE-2018-13896 affects various Qualcomm Snapdragon chips, including the MDM9206, MDM9607, and several others across automotive, connectivity, and consumer electronics.
What are the potential impacts of exploiting CVE-2018-13896?
Exploitation of CVE-2018-13896 could lead to unauthorized access to sensitive data or the ability to execute arbitrary code within the affected device.
Is there public information available about CVE-2018-13896?
Yes, further details about CVE-2018-13896 are documented in security bulletins from both Qualcomm and Android.