CVE-2018-13908: High severity android vulnerability
Truncated access authentication token leads to weakened access control for stored secure application data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in IPQ8074, MDM9150, MDM9206, MDM9607, MDM9650, MDM9655, MSM8909W, MSM8996AU, QCA8081, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM439, SDM630, SDM660, SnapdragonHighMed2016, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13908?
CVE-2018-13908 has been categorized with a severity level that indicates a potential impact on access control for stored secure application data.
How do I fix CVE-2018-13908?
To mitigate CVE-2018-13908, it is recommended to update your affected Qualcomm firmware to the latest version that addresses this vulnerability.
Which products are affected by CVE-2018-13908?
CVE-2018-13908 affects various Qualcomm products including Snapdragon Auto, Compute, and several other IoT devices.
What type of vulnerability is CVE-2018-13908?
CVE-2018-13908 is a vulnerability associated with truncated access authentication tokens leading to weakened access controls.
Are there any workarounds for CVE-2018-13908?
While updating firmware is the primary solution for CVE-2018-13908, specific workarounds may depend on the individual device and its configuration.