PT-2018-1251 · Qualcomm+1 · Qualcomm Snapdragon Mobile Mdm9625+4

Published

2018-04-02

·

Updated

2018-05-01

·

CVE-2015-9215

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions prior to 2018-04-05 security patch level Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, and SD 810 (affected versions not specified)
Description The issue is related to the find ep() function in the Qualcomm USB Bootloader component of the Android operating system, which is vulnerable to a null pointer dereference. This could allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is caused by improper input validation.
Recommendations For Android versions prior to 2018-04-05 security patch level, update to a version with a security patch level of 2018-04-05 or later. For Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, and SD 810, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00724
CVE-2015-9215

Affected Products

Android
Qualcomm Snapdragon Mobile Mdm9615
Qualcomm Snapdragon Mobile Mdm9625
Qualcomm Snapdragon Mobile Mdm9635M
Sd 810