CVE-2018-13904

Improper input validation in SCM handler to access storage in TZ can lead to unauthorized access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9206, MDM9607, MDM9650, MDM9655, QCS605, SD 410/12, SD 675, SD 712 / SD 710 / SD 670, SD 8CX, SXR1130.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
qualcommCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
VendorProductVersion
qualcommmdm9206_firmware
-
qualcommmdm9607_firmware
-
qualcommmdm9650_firmware
-
qualcommmdm9655_firmware
-
qualcommqcs605_firmware
-
qualcommsd_410_firmware
-
qualcommsd_12_firmware
-
qualcommsd_675_firmware
-
qualcommsd_712_firmware
-
qualcommsd_710_firmware
-
qualcommsd_670_firmware
-
qualcommsd_8cx_firmware
-
qualcommsxr1130_firmware
-
𝑥
= Vulnerable software versions