CVE-2018-13901: Medium severity android vulnerability
Due to missing permissions in Android Manifest file, Sensitive information disclosure issue can happen in PCI RCS app in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, QCA6574AU, QCS605, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM630, SDM660
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-13901?
CVE-2018-13901 is a vulnerability that can lead to sensitive information disclosure in the PCI RCS app in various Qualcomm products running Android.
How severe is CVE-2018-13901?
CVE-2018-13901 has a severity level of high with a CVSS score of 5.5.
Which products are affected by CVE-2018-13901?
CVE-2018-13901 affects the PCI RCS app in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, and Snapdragon Wearables.
How can the sensitive information disclosure issue be fixed in the affected products?
To fix the sensitive information disclosure issue in the affected products, it is recommended to apply the necessary security patches provided by Qualcomm and Google.
Where can I find more information about CVE-2018-13901?
You can find more information about CVE-2018-13901 on the Qualcomm Product Security Bulletins and Android Security Bulletins websites.