PT-2018-4320 · Qualcomm+1 · Sd 808+26

Published

2018-04-18

·

Updated

2018-05-11

·

CVE-2014-9989

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions prior to 2018-04-05 security patch level
Description The issue arises when an incorrect endpoint number or direction is passed, potentially leading to an out of bounds array access in the USB management module of affected Qualcomm Snapdragon Mobile and Snapdragon Wear devices, including MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 600, SD 615/16/SD 415, SD 625, SD 650/52, SD 808, SD 810, and SD 450.
Recommendations For Android versions prior to 2018-04-05 security patch level, update to a version with a security patch level of 2018-04-05 or later to resolve the issue. As a temporary workaround, consider restricting access to the USB management module to minimize the risk of exploitation.

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-9989

Affected Products

Android
Mdm9206
Mdm9607
Mdm9615
Mdm9625
Mdm9635M
Msm8909W
Qualcomm Snapdragon Mobile
Qualcomm Snapdragon Wear
Sd 205
Sd 210
Sd 212
Sd 400
Sd 410
Sd 412
Sd 415
Sd 425
Sd 430
Sd 450
Sd 600
Sd 615
Sd 616
Sd 625
Sd 650
Sd 652
Sd 808
Sd 810