CVE-2018-20823: Input Validation
Published Apr 25, 2019
·Updated
The gyroscope on Xiaomi Mi 5s devices allows attackers to cause a denial of service (resonance and false data) via a 20.4 kHz audio signal, aka a MEMS ultrasound attack.
Affected Software
2 affected components
Mi Mi 5s Firmware
Mi Mi 5s
Event History
Apr 25, 2019
CVE Published
via MITRE·01:47 PM
Data Sourced
via MITRE·01:47 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20823?
CVE-2018-20823 has a high severity as it can lead to denial of service via a MEMS ultrasound attack on the gyroscope.
2
How do I fix CVE-2018-20823?
To mitigate CVE-2018-20823, it is recommended to avoid exposure to 20.4 kHz audio signals and implement software patches from Xiaomi.
3
What devices are affected by CVE-2018-20823?
CVE-2018-20823 specifically affects Xiaomi Mi 5s devices.
4
Can CVE-2018-20823 be triggered remotely?
Yes, CVE-2018-20823 can be triggered remotely using a 20.4 kHz audio signal.
5
What type of attack is CVE-2018-20823 classified as?
CVE-2018-20823 is classified as a denial of service attack.