CVE-2018-11940

EUVD-2018-3932
Lack of check in length before using memcpy in WLAN function can lead to OOB access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCS605, SD 625, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM630, SDM660, SDX20, SDX24, SXR1130
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
Affected Products (NVD)
VendorProductVersion
qualcommmdm9150_firmware
-
qualcommmdm9206_firmware
-
qualcommmdm9607_firmware
-
qualcommmdm9640_firmware
-
qualcommmdm9650_firmware
-
qualcommmsm8996au_firmware
-
qualcommqcs605_firmware
-
qualcommsd_625_firmware
-
qualcommsd_636_firmware
-
qualcommsd_712_firmware
-
qualcommsd_710_firmware
-
qualcommsd_670_firmware
-
qualcommsd_820_firmware
-
qualcommsd_820a_firmware
-
qualcommsd_835_firmware
-
qualcommsd_845_firmware
-
qualcommsd_850_firmware
-
qualcommsd_855_firmware
-
qualcommsda660_firmware
-
qualcommsdm630_firmware
-
qualcommsdm660_firmware
-
qualcommsdx20_firmware
-
qualcommsdx24_firmware
-
qualcommsxr1130_firmware
-
𝑥
= Vulnerable software versions