PT-2019-8782 · Qualcomm · Snapdragon Wear+1
Published
2019-01-18
·
Updated
2019-10-03
·
CVE-2018-11284
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Qualcomm Snapdragon Mobile and Snapdragon Wear versions MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 625, SD 636, SDA660, SDM630, SDM660, SDX20
Description
The issue allows spoofed SMS messages to be sent to a device, triggering a large number of registration updates with the server. This can lead to a flood of updates.
Recommendations
For versions MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 625, SD 636, SDA660, SDM630, SDM660, SDX20, consider implementing rate limiting on registration updates to prevent flooding.
As a temporary workaround, consider restricting the processing of SMS messages from unknown sources until a patch is available.
Restrict access to the registration update mechanism to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snapdragon Mobile
Snapdragon Wear