CVE-2018-12012 Information

Description

While updating blacklisting region shared buffered memory region is not validated against newly updated black list causing boot-up to be compromised in Snapdragon Auto Snapdragon Compute Snapdragon Consumer Electronics Connectivity Snapdragon Consumer IOT Snapdragon Industrial IOT Snapdragon Mobile Snapdragon Voice & Music Snapdragon Wearables in MDM9206 MDM9607 MDM9650 MDM9655 QCS605 SD 210/SD 212/SD 205 SD 410/12 SD 615/16/SD 415 SD 712 / SD 710 / SD 670 SD 835 SD 845 / SD 850 SD 8CX SXR1130

CVSS Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://www.qualcomm.com/company/product-security/bulletins_CVE-2018-12012

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.8

Share on: