CVE-2018-5837: Weak RNG
In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, SnapdragonHighMed2016, MAC address randomization performed during probe requests is not done properly due to a flawed RNG which produced repeating output much earlier than expected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5837?
The severity of CVE-2018-5837 is high with a severity value of 7.5.
What software is affected by CVE-2018-5837?
The affected software includes Google Android, Qualcomm IPQ8074 Firmware, Qualcomm MDM9206 Firmware, Qualcomm MDM9607 Firmware, Qualcomm MDM9640 Firmware, Qualcomm MDM9650 Firmware, Qualcomm MSM8996AU Firmware, Qualcomm QCA6574AU Firmware, Qualcomm SD 210/SD 212/SD 205 Firmware, Qualcomm SD 425 Firmware, Qualcomm SD 427 Firmware, Qualcomm SD 430 Firmware, Qualcomm SD 435 Firmware, Qualcomm SD 450 Firmware, Qualcomm SD 625 Firmware, Qualcomm SD 820A Firmware, Qualcomm SD 835 Firmware, Qualcomm SD 845 Firmware, Qualcomm SD 850 Firmware, Qualcomm SDA660 Firmware, Qualcomm SDM429 Firmware, Qualcomm SDM439 Firmware, Qualcomm SDM630 Firmware, Qualcomm SDM632 Firmware, Qualcomm SDM636 Firmware, Qualcomm SDM660 Firmware, and Qualcomm SDM710 Firmware.
How do I fix CVE-2018-5837?
To fix CVE-2018-5837, it is recommended to apply the relevant security patches provided by the software vendors or follow the mitigation steps provided in the security bulletin.
Where can I find more information about CVE-2018-5837?
You can find more information about CVE-2018-5837 in the security bulletin: [link]
What is the Common Weakness Enumeration (CWE) associated with CVE-2018-5837?
The Common Weakness Enumeration (CWE) associated with CVE-2018-5837 is CWE-338.