CVE-2018-13913

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/02/2019
Last modified:
26/02/2019

Description

Improper validation of array index can lead to unauthorized access while processing debugFS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in version MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 615/16/SD 415, SD 625, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:qualcomm:snapdragon_auto_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_auto:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_consumer_internet_of_things_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_consumer_internet_of_things:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_industrial_internet_of_things_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_industrial_internet_of_things:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_internet_of_things_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_internet_of_things:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_mobile_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_mobile:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_voice_\&_music_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_voice_\&_music:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:mdm9150_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:mdm9150:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:*