PT-2019-11002 · Qualcomm · Qualcomm Sd 450+57

Published

2019-06-14

·

Updated

2019-06-17

·

CVE-2018-5913

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Qualcomm Snapdragon Auto versions MDM9150 through MDM9655 Qualcomm Snapdragon Compute versions MDM9150 through MDM9655 Qualcomm Snapdragon Connectivity versions MDM9150 through MDM9655 Qualcomm Snapdragon Consumer Electronics Connectivity versions MDM9150 through MDM9655 Qualcomm Snapdragon Consumer IOT versions MDM9150 through MDM9655 Qualcomm Snapdragon Industrial IOT versions MDM9150 through MDM9655 Qualcomm Snapdragon IoT versions MDM9150 through MDM9655 Qualcomm Snapdragon Mobile versions MDM9150 through MDM9655 Qualcomm Snapdragon Voice & Music versions MDM9150 through MDM9655 Qualcomm Snapdragon Wearables versions MDM9150 through MDM9655 Qualcomm MDM9150 Qualcomm MDM9206 Qualcomm MDM9607 Qualcomm MDM9625 Qualcomm MDM9635M Qualcomm MDM9640 Qualcomm MDM9650 Qualcomm MDM9655 Qualcomm MSM8909W Qualcomm MSM8996AU Qualcomm QCS405 Qualcomm QCS605 Qualcomm 215 Qualcomm SD 210 Qualcomm SD 212 Qualcomm SD 205 Qualcomm SD 410 Qualcomm SD 412 Qualcomm SD 425 Qualcomm SD 427 Qualcomm SD 430 Qualcomm SD 435 Qualcomm SD 439 Qualcomm SD 429 Qualcomm SD 450 Qualcomm SD 615 Qualcomm SD 616 Qualcomm SD 415 Qualcomm SD 625 Qualcomm SD 632 Qualcomm SD 636 Qualcomm SD 650 Qualcomm SD 652 Qualcomm SD 675 Qualcomm SD 712 Qualcomm SD 710 Qualcomm SD 670 Qualcomm SD 730 Qualcomm SD 820 Qualcomm SD 820A Qualcomm SD 835 Qualcomm SD 845 Qualcomm SD 850 Qualcomm SD 855 Qualcomm SD 8CX Qualcomm SDA660 Qualcomm SDM439 Qualcomm SDM630 Qualcomm SDM660 Qualcomm Snapdragon High Med 2016 Qualcomm SXR1130
Description: A non-time constant function memcmp is used, which creates a side channel that could leak information.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5913

Affected Products

Qualcomm 215
Qualcomm Mdm9150
Qualcomm Mdm9206
Qualcomm Mdm9607
Qualcomm Mdm9625
Qualcomm Mdm9635M
Qualcomm Mdm9640
Qualcomm Mdm9650
Qualcomm Mdm9655
Qualcomm Msm8909W
Qualcomm Msm8996Au
Qualcomm Qcs405
Qualcomm Qcs605
Qualcomm Sd 205
Qualcomm Sd 210
Qualcomm Sd 212
Qualcomm Sd 410
Qualcomm Sd 412
Qualcomm Sd 415
Qualcomm Sd 425
Qualcomm Sd 427
Qualcomm Sd 429
Qualcomm Sd 430
Qualcomm Sd 435
Qualcomm Sd 439
Qualcomm Sd 450
Qualcomm Sd 615
Qualcomm Sd 616
Qualcomm Sd 625
Qualcomm Sd 632
Qualcomm Sd 636
Qualcomm Sd 650
Qualcomm Sd 652
Qualcomm Sd 670
Qualcomm Sd 675
Qualcomm Sd 710
Qualcomm Sd 712
Qualcomm Sd 730
Qualcomm Sd 820A
Qualcomm Sd 835
Qualcomm Sd 845
Qualcomm Sd 850
Qualcomm Sd 855
Qualcomm Sd 8Cx
Qualcomm Sdm660
Qualcomm Sdm630
Qualcomm Sxr1130
Qualcomm Snapdragon Auto
Qualcomm Snapdragon Compute
Qualcomm Snapdragon Connectivity
Qualcomm Snapdragon Consumer Electronics Connectivity
Qualcomm Snapdragon Consumer Iot
Qualcomm Snapdragon Industrial Iot
Qualcomm Snapdragon
Qualcomm Snapdragon Mobile
Qualcomm Snapdragon Voice & Music
Qualcomm Snapdragon Wearables
Qualcomm Snapdragon High Med 2016