CVE-2018-3591: Critical severity android vulnerability
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 835, SD 845, SDM630, SDM636, SDM660, SnapdragonHighMed2016, the default build configuration of deviceprogrammer in BOOT.BF.3.0 enables the flag SKIPSECBOOTCHECKNOTRECOMMENDEDBYQUALCOMM which will open up the peek and poke commands to any memory location on the target.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3591?
CVE-2018-3591 has a severity rating defined as critical, impacting multiple Qualcomm Snapdragon Mobile and Wear devices.
How do I fix CVE-2018-3591?
To mitigate CVE-2018-3591, update your device to the latest firmware or security patch level released after April 5, 2018.
Which devices are affected by CVE-2018-3591?
CVE-2018-3591 affects various Qualcomm Snapdragon Mobile and Wear devices, including models like MDM9206, MDM9607, and more.
What type of vulnerability is CVE-2018-3591?
CVE-2018-3591 is classified as a memory corruption vulnerability that can allow attackers to execute arbitrary code.
Is there a workaround for CVE-2018-3591?
There are no specific workarounds for CVE-2018-3591; the best solution is to apply the latest updates from the device manufacturer.