PT-2018-10920 · Qualcomm · Snapdragon Mobile
Publicado
2018-10-26
·
Atualizado
2019-10-03
·
CVE-2018-11951
CVSS v2.0
4.9
Média
| Vetor | AV:L/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Snapdragon Mobile versions SD 845, SD 850
Description
The issue is related to improper access control in the core module, specifically with XBL LOADER performing the ZI region clear for QTEE instead of XBL SEC. This affects the security of the system.
Recommendations
For versions SD 845 and SD 850, consider restricting access to the core module to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Snapdragon Mobile