PT-2019-8782 · Qualcomm · Snapdragon Wear+1

Published

2019-01-18

·

Updated

2019-10-03

·

CVE-2018-11284

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon Mobile and Snapdragon Wear versions MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 625, SD 636, SDA660, SDM630, SDM660, SDX20
Description The issue allows spoofed SMS messages to be sent to a device, triggering a large number of registration updates with the server. This can lead to a flood of updates.
Recommendations For versions MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 625, SD 636, SDA660, SDM630, SDM660, SDX20, consider implementing rate limiting on registration updates to prevent flooding. As a temporary workaround, consider restricting the processing of SMS messages from unknown sources until a patch is available. Restrict access to the registration update mechanism to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-11284

Affected Products

Snapdragon Mobile
Snapdragon Wear