First published: Mon Jul 02 2018(Updated: )
In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, Snapdragon_High_Med_2016, MAC address randomization performed during probe requests is not done properly due to a flawed RNG which produced repeating output much earlier than expected.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
qualcomm ipq8074 firmware | ||
Qualcomm IPQ8074A | ||
Qualcomm MDM9206 | ||
Qualcomm MDM9206 firmware | ||
Qualcomm MD9607 Firmware | ||
Qualcomm MDM9607 firmware | ||
Qualcomm MDM9640 Firmware | ||
Qualcomm MDM9640 Firmware | ||
Qualcomm MDM9650 | ||
Qualcomm MDM9650 firmware | ||
qualcomm MSM8996AU firmware | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm QCA6574 Firmware | ||
Qualcomm QCA6574AU | ||
Qualcomm SD 210 Firmware | ||
Qualcomm SD210 Firmware | ||
Qualcomm SD 212 Firmware | ||
Qualcomm SD 212 | ||
Qualcomm 205 Firmware | ||
Qualcomm Snapdragon 205 | ||
Qualcomm SD425 Firmware | ||
Qualcomm Snapdragon 425 | ||
Qualcomm SD 427 firmware | ||
Qualcomm SD427 Firmware | ||
Qualcomm SD 430 Firmware | ||
Qualcomm Snapdragon 430 | ||
Qualcomm Snapdragon 435 Firmware | ||
Qualcomm Snapdragon 435 | ||
Qualcomm SD 450 Firmware | ||
Qualcomm Snapdragon 450 | ||
Qualcomm SD 625 Firmware | ||
Qualcomm Snapdragon 625 | ||
Qualcomm SD 820A firmware | ||
Qualcomm SD820A Firmware | ||
Qualcomm Snapdragon 835 | ||
Qualcomm Snapdragon 835 | ||
Qualcomm SDA845 Firmware | ||
Qualcomm Snapdragon 845 | ||
Qualcomm SD850 Firmware | ||
Qualcomm Snapdragon 850 | ||
Qualcomm SDA660 | ||
Qualcomm SDA660 | ||
Qualcomm SDM429W | ||
Qualcomm SD429 | ||
Qualcomm SDM439 Firmware | ||
Qualcomm SDM439 Firmware | ||
Qualcomm SDM630 | ||
Qualcomm SDM630 Firmware | ||
Qualcomm SDM632 Firmware | ||
Qualcomm SDM632 Firmware | ||
Qualcomm SD 636 Firmware | ||
Qualcomm SDM636 Firmware | ||
Qualcomm SD660 Firmware | ||
Qualcomm Snapdragon 660 | ||
Qualcomm SD 710 Firmware | ||
Qualcomm Snapdragon 710 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-5837 is high with a severity value of 7.5.
The affected software includes Google Android, Qualcomm IPQ8074 Firmware, Qualcomm MDM9206 Firmware, Qualcomm MDM9607 Firmware, Qualcomm MDM9640 Firmware, Qualcomm MDM9650 Firmware, Qualcomm MSM8996AU Firmware, Qualcomm QCA6574AU Firmware, Qualcomm SD 210/SD 212/SD 205 Firmware, Qualcomm SD 425 Firmware, Qualcomm SD 427 Firmware, Qualcomm SD 430 Firmware, Qualcomm SD 435 Firmware, Qualcomm SD 450 Firmware, Qualcomm SD 625 Firmware, Qualcomm SD 820A Firmware, Qualcomm SD 835 Firmware, Qualcomm SD 845 Firmware, Qualcomm SD 850 Firmware, Qualcomm SDA660 Firmware, Qualcomm SDM429 Firmware, Qualcomm SDM439 Firmware, Qualcomm SDM630 Firmware, Qualcomm SDM632 Firmware, Qualcomm SDM636 Firmware, Qualcomm SDM660 Firmware, and Qualcomm SDM710 Firmware.
To fix CVE-2018-5837, it is recommended to apply the relevant security patches provided by the software vendors or follow the mitigation steps provided in the security bulletin.
You can find more information about CVE-2018-5837 in the security bulletin: [link]
The Common Weakness Enumeration (CWE) associated with CVE-2018-5837 is CWE-338.