First published: Mon Jul 02 2018(Updated: )
In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, Snapdragon_High_Med_2016, MAC address randomization performed during probe requests is not done properly due to a flawed RNG which produced repeating output much earlier than expected.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Ipq8074 Firmware | ||
Qualcomm Ipq8074 | ||
Qualcomm Mdm9206 Firmware | ||
Qualcomm Mdm9206 | ||
Qualcomm Mdm9607 Firmware | ||
Qualcomm Mdm9607 | ||
Qualcomm Mdm9640 Firmware | ||
Qualcomm Mdm9640 | ||
Qualcomm Mdm9650 Firmware | ||
Qualcomm Mdm9650 | ||
Qualcomm Msm8996au Firmware | ||
Qualcomm Msm8996au | ||
Qualcomm Qca6574au Firmware | ||
Qualcomm Qca6574au | ||
Qualcomm Sd210 Firmware | ||
Qualcomm Sd210 | ||
Qualcomm Sd212 Firmware | ||
Qualcomm Sd212 | ||
Qualcomm Sd205 Firmware | ||
Qualcomm Sd205 | ||
Qualcomm Sd425 Firmware | ||
Qualcomm Sd425 | ||
Qualcomm Sd427 Firmware | ||
Qualcomm Sd427 | ||
Qualcomm Sd430 Firmware | ||
Qualcomm Sd430 | ||
Qualcomm Sd435 Firmware | ||
Qualcomm Sd435 | ||
Qualcomm Sd450 Firmware | ||
Qualcomm Sd450 | ||
Qualcomm Sd625 Firmware | ||
Qualcomm Sd625 | ||
Qualcomm Sd820a Firmware | ||
Qualcomm Sd820a | ||
Qualcomm Sd835 Firmware | ||
Qualcomm Sd835 | ||
Qualcomm Sd845 Firmware | ||
Qualcomm Sd845 | ||
Qualcomm Sd850 Firmware | ||
Qualcomm Sd850 | ||
Qualcomm Sda660 Firmware | ||
Qualcomm Sda660 | ||
Qualcomm Sdm429 Firmware | ||
Qualcomm Sdm429 | ||
Qualcomm Sdm439 Firmware | ||
Qualcomm Sdm439 | ||
Qualcomm Sdm630 Firmware | ||
Qualcomm Sdm630 | ||
Qualcomm Sdm632 Firmware | ||
Qualcomm Sdm632 | ||
Qualcomm Sdm636 Firmware | ||
Qualcomm Sdm636 | ||
Qualcomm Sdm660 Firmware | ||
Qualcomm Sdm660 | ||
Qualcomm Sdm710 Firmware | ||
Qualcomm Sdm710 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-5837 is high with a severity value of 7.5.
The affected software includes Google Android, Qualcomm IPQ8074 Firmware, Qualcomm MDM9206 Firmware, Qualcomm MDM9607 Firmware, Qualcomm MDM9640 Firmware, Qualcomm MDM9650 Firmware, Qualcomm MSM8996AU Firmware, Qualcomm QCA6574AU Firmware, Qualcomm SD 210/SD 212/SD 205 Firmware, Qualcomm SD 425 Firmware, Qualcomm SD 427 Firmware, Qualcomm SD 430 Firmware, Qualcomm SD 435 Firmware, Qualcomm SD 450 Firmware, Qualcomm SD 625 Firmware, Qualcomm SD 820A Firmware, Qualcomm SD 835 Firmware, Qualcomm SD 845 Firmware, Qualcomm SD 850 Firmware, Qualcomm SDA660 Firmware, Qualcomm SDM429 Firmware, Qualcomm SDM439 Firmware, Qualcomm SDM630 Firmware, Qualcomm SDM632 Firmware, Qualcomm SDM636 Firmware, Qualcomm SDM660 Firmware, and Qualcomm SDM710 Firmware.
To fix CVE-2018-5837, it is recommended to apply the relevant security patches provided by the software vendors or follow the mitigation steps provided in the security bulletin.
You can find more information about CVE-2018-5837 in the security bulletin: [link]
The Common Weakness Enumeration (CWE) associated with CVE-2018-5837 is CWE-338.