CVE-2018-3595: Medium severity android vulnerability
Anti-rollback can be bypassed in replay scenario during app loading due to improper error handling of RPMB writes in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX24, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-3595?
CVE-2018-3595 is a vulnerability that allows for anti-rollback to be bypassed during app loading on certain Qualcomm devices.
What is the severity of CVE-2018-3595?
The severity of CVE-2018-3595 is high with a severity value of 5.5.
Which devices are affected by CVE-2018-3595?
Snapdragon automobile, Snapdragon mobile, and Snapdragon wear devices with versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 712 are affected.
How can I fix CVE-2018-3595?
To fix CVE-2018-3595, apply the necessary firmware updates provided by Qualcomm and Google.
Where can I find more information about CVE-2018-3595?
You can find more information about CVE-2018-3595 in the Android Security Bulletin for December 2018.