CVE-2018-13897: Infoleak
Clients hostname gets added to DNS record on device which is running dnsmasq resulting in an information exposure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 625, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 855, SDA660, SDM630, SDM660
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-13897?
CVE-2018-13897 is a vulnerability that allows clients' hostname to be added to a DNS record on a device running dnsmasq, resulting in an information exposure in various Qualcomm products.
Which products are affected by CVE-2018-13897?
Qualcomm Mdm9206 Firmware, Qualcomm Mdm9640 Firmware, Qualcomm Mdm9650 Firmware, Qualcomm Qcs605 Firmware, Qualcomm Sd 210 Firmware, Qualcomm Sd 212 Firmware, Qualcomm Sd 205 Firmware, Qualcomm Sd 616 Firmware, Qualcomm Sd 415 Firmware, Qualcomm Sd 625 Firmware, Qualcomm Sd 636 Firmware, Qualcomm Sd 712 Firmware, Qualcomm Sd 710 Firmware, Qualcomm Sd 670 Firmware, Qualcomm Sd 730 Firmware, Qualcomm Sd 820a Firmware, Qualcomm Sd 835 Firmware, Qualcomm Sd 855 Firmware, Qualcomm Sdm630 Firmware, Qualcomm Sdm660 Firmware.
What is the severity of CVE-2018-13897?
The severity of CVE-2018-13897 is high with a CVSS score of 7.5.
How does CVE-2018-13897 work?
CVE-2018-13897 allows an attacker to exploit the dnsmasq vulnerability and add clients' hostname to a DNS record, leading to an information exposure.
Is there a fix available for CVE-2018-13897?
To fix CVE-2018-13897, users should update their devices with the latest firmware or software patches provided by Qualcomm.