PT-2018-1251 · Qualcomm+1 · Qualcomm Snapdragon Mobile Mdm9625+4
Published
2018-04-02
·
Updated
2018-05-01
·
CVE-2015-9215
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions prior to 2018-04-05 security patch level
Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, and SD 810 (affected versions not specified)
Description
The issue is related to the
find ep() function in the Qualcomm USB Bootloader component of the Android operating system, which is vulnerable to a null pointer dereference. This could allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is caused by improper input validation.Recommendations
For Android versions prior to 2018-04-05 security patch level, update to a version with a security patch level of 2018-04-05 or later.
For Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, and SD 810, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Qualcomm Snapdragon Mobile Mdm9615
Qualcomm Snapdragon Mobile Mdm9625
Qualcomm Snapdragon Mobile Mdm9635M
Sd 810