CVE-2018-5839
HIGHSnapdragon Auto/Mobile/Compute/IOT - Memory Corruption
Title source: llmDescription
Improperly configured memory protection allows read/write access to modem image from HLOS kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9150, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8996AU, QCS605, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SDX20, SXR1130.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://www.qualcomm.com/company/product-security/bulletins
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/106845
Scores
CVSS v3
7.1
EPSS
0.0008
EPSS Percentile
23.9%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-269
Status
published
Products (30)
qualcomm/mdm9150_firmware
qualcomm/mdm9615_firmware
qualcomm/mdm9625_firmware
qualcomm/mdm9635m_firmware
qualcomm/mdm9640_firmware
qualcomm/mdm9650_firmware
qualcomm/mdm9655_firmware
qualcomm/msm8996au_firmware
qualcomm/qcs605_firmware
qualcomm/sd_636_firmware
... and 20 more
Published
Feb 25, 2019
Tracked Since
Feb 18, 2026