CVE-2018-11292

In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCA6574AU, QCA6584, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820A, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016, lack of input validation in WLANWMI command handlers can lead to integer & heap overflows.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
qualcommCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
VendorProductVersion
qualcommmdm9206_firmware
-
qualcommmdm9607_firmware
-
qualcommmdm9640_firmware
-
qualcommmdm9650_firmware
-
qualcommmsm8909w_firmware
-
qualcommmsm8996au_firmware
-
qualcommqca6574au_firmware
-
qualcommqca6584_firmware
-
qualcommsd210_firmware
-
qualcommsd212_firmware
-
qualcommsd205_firmware
-
qualcommsd410_firmware
-
qualcommsd412_firmware
-
qualcommsd425_firmware
-
qualcommsd427_firmware
-
qualcommsd430_firmware
-
qualcommsd450_firmware
-
qualcommsd615_firmware
-
qualcommsd616_firmware
-
qualcommsd415_firmware
-
qualcommsd625_firmware
-
qualcommsd650_firmware
-
qualcommsd652_firmware
-
qualcommsd820a_firmware
-
qualcommsdm429_firmware
-
qualcommsdm439_firmware
-
qualcommsdm630_firmware
-
qualcommsdm632_firmware
-
qualcommsdm636_firmware
-
qualcommsdm660_firmware
-
𝑥
= Vulnerable software versions