7.8

CVE-2018-11855

If an end user makes use of SCP11 sample OCE code without modification it could lead to a buffer overflow when transmitting a CAPDU in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT and Snapdragon Mobile in versions MDM9607, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 636, SD 820, SD 820A, SD 835, SD 8CX, SDA660, SDM630, SDM660.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QualcommMdm9607 Firmware Version-
   QualcommMdm9607 Version-
QualcommMdm9650 Firmware Version-
   QualcommMdm9650 Version-
QualcommMdm9655 Firmware Version-
   QualcommMdm9655 Version-
QualcommMsm8996au Firmware Version-
   QualcommMsm8996au Version-
QualcommSd 210 Firmware Version-
   QualcommSd 210 Version-
QualcommSd 212 Firmware Version-
   QualcommSd 212 Version-
QualcommSd 205 Firmware Version-
   QualcommSd 205 Version-
QualcommSd 410 Firmware Version-
   QualcommSd 410 Version-
QualcommSd 412 Firmware Version-
   QualcommSd 412 Version-
QualcommSd 636 Firmware Version-
   QualcommSd 636 Version-
QualcommSd 820 Firmware Version-
   QualcommSd 820 Version-
QualcommSd 820a Firmware Version-
   QualcommSd 820a Version-
QualcommSd 835 Firmware Version-
   QualcommSd 835 Version-
QualcommSd 8cx Firmware Version-
   QualcommSd 8cx Version-
QualcommSda660 Firmware Version-
   QualcommSda660 Version-
QualcommSdm630 Firmware Version-
   QualcommSdm630 Version-
QualcommSdm660 Firmware Version-
   QualcommSdm660 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.066
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.