7.8

CVE-2018-13908

Truncated access authentication token leads to weakened access control for stored secure application data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in IPQ8074, MDM9150, MDM9206, MDM9607, MDM9650, MDM9655, MSM8909W, MSM8996AU, QCA8081, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016, SXR1130

Data is provided by the National Vulnerability Database (NVD)
QualcommIpq8074 Firmware Version-
   QualcommIpq8074 Version-
QualcommMdm9150 Firmware Version-
   QualcommMdm9150 Version-
QualcommMdm9206 Firmware Version-
   QualcommMdm9206 Version-
QualcommMdm9607 Firmware Version-
   QualcommMdm9607 Version-
QualcommMdm9650 Firmware Version-
   QualcommMdm9650 Version-
QualcommMdm9655 Firmware Version-
   QualcommMdm9655 Version-
QualcommMsm8909w Firmware Version-
   QualcommMsm8909w Version-
QualcommMsm8996au Firmware Version-
   QualcommMsm8996au Version-
QualcommQca8081 Firmware Version-
   QualcommQca8081 Version-
QualcommQcs405 Firmware Version-
   QualcommQcs405 Version-
QualcommQm215 Firmware Version-
   QualcommQm215 Version-
QualcommSd 210 Firmware Version-
   QualcommSd 210 Version-
QualcommSd 212 Firmware Version-
   QualcommSd 212 Version-
QualcommSd 205 Firmware Version-
   QualcommSd 205 Version-
QualcommSd 410 Firmware Version-
   QualcommSd 410 Version-
QualcommSd 412 Firmware Version-
   QualcommSd 412 Version-
QualcommSd 425 Firmware Version-
   QualcommSd 425 Version-
QualcommSd 427 Firmware Version-
   QualcommSd 427 Version-
QualcommSd 430 Firmware Version-
   QualcommSd 430 Version-
QualcommSd 435 Firmware Version-
   QualcommSd 435 Version-
QualcommSd 439 Firmware Version-
   QualcommSd 439 Version-
QualcommSd 429 Firmware Version-
   QualcommSd 429 Version-
QualcommSd 450 Firmware Version-
   QualcommSd 450 Version-
QualcommSd 615 Firmware Version-
   QualcommSd 615 Version-
QualcommSd 616 Firmware Version-
   QualcommSd 616 Version-
QualcommQcs605 Firmware Version-
   QualcommQcs605 Version-
QualcommSd 415 Firmware Version-
   QualcommSd 415 Version-
QualcommSd 625 Firmware Version-
   QualcommSd 625 Version-
QualcommSd 632 Firmware Version-
   QualcommSd 632 Version-
QualcommSd 636 Firmware Version-
   QualcommSd 636 Version-
QualcommSd 650 Firmware Version-
   QualcommSd 650 Version-
QualcommSd 652 Firmware Version-
   QualcommSd 652 Version-
QualcommSd 712 Firmware Version-
   QualcommSd 712 Version-
QualcommSd 710 Firmware Version-
   QualcommSd 710 Version-
QualcommSd 670 Firmware Version-
   QualcommSd 670 Version-
QualcommSd 820 Firmware Version-
   QualcommSd 820 Version-
QualcommSd 820a Firmware Version-
   QualcommSd 820a Version-
QualcommSd 835 Firmware Version-
   QualcommSd 835 Version-
QualcommSd 845 Firmware Version-
   QualcommSd 845 Version-
QualcommSd 850 Firmware Version-
   QualcommSd 850 Version-
QualcommSd 8cx Firmware Version-
   QualcommSd 8cx Version-
QualcommSda660 Firmware Version-
   QualcommSda660 Version-
QualcommSdm439 Firmware Version-
   QualcommSdm439 Version-
QualcommSdm630 Firmware Version-
   QualcommSdm630 Version-
QualcommSdm660 Firmware Version-
   QualcommSdm660 Version-
QualcommSxr1130 Firmware Version-
   QualcommSxr1130 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.131
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-285 Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.