SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-5917

Possible buffer overflow in OEM crypto function due to improper input validation in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996AU, SD 425, SD 430, SD 450, SD 625, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDA845, SDX24, SXR1130.

HIGH 7.8EPSS 0.26%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Possible buffer overflow in OEM crypto function due to improper input validation in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996AU, SD 425, SD 430, SD 450, SD 625, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDA845, SDX24, SXR1130.

CVSS 3.0
7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.26% probability · 18th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
qualcomm/msm8996au firmware · qualcomm/sd 425 firmware · qualcomm/sd 430 firmware · qualcomm/sd 450 firmware · qualcomm/sd 625 firmware · qualcomm/sd 820 firmware · qualcomm/sd 820a firmware · qualcomm/sd 835 firmware · qualcomm/sd 845 firmware · qualcomm/sd 850 firmware · qualcomm/sda660 firmware · qualcomm/sda845 firmware · qualcomm/sdx24 firmware · qualcomm/sxr1130 firmware
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.