6.5

CVE-2018-5871

In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, Snapdragon_High_Med_2016, MAC address randomization performed during probe requests (for privacy reasons) is not done properly due to a flawed RNG which produces repeating output much earlier than expected.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QualcommMdm9206 Firmware Version-
   QualcommMdm9206 Version-
QualcommMdm9607 Firmware Version-
   QualcommMdm9607 Version-
QualcommMdm9640 Firmware Version-
   QualcommMdm9640 Version-
QualcommMdm9650 Firmware Version-
   QualcommMdm9650 Version-
QualcommMsm8996au Firmware Version-
   QualcommMsm8996au Version-
QualcommQca6574au Firmware Version-
   QualcommQca6574au Version-
QualcommSd210 Firmware Version-
   QualcommSd210 Version-
QualcommSd212 Firmware Version-
   QualcommSd212 Version-
QualcommSd205 Firmware Version-
   QualcommSd205 Version-
QualcommSd425 Firmware Version-
   QualcommSd425 Version-
QualcommSd427 Firmware Version-
   QualcommSd427 Version-
QualcommSd430 Firmware Version-
   QualcommSd430 Version-
QualcommSd435 Firmware Version-
   QualcommSd435 Version-
QualcommSd450 Firmware Version-
   QualcommSd450 Version-
QualcommSd615 Firmware Version-
   QualcommSd615 Version-
QualcommSd616 Firmware Version-
   QualcommSd616 Version-
QualcommSd415 Firmware Version-
   QualcommSd415 Version-
QualcommSd650 Firmware Version-
   QualcommSd650 Version-
QualcommSd652 Firmware Version-
   QualcommSd652 Version-
QualcommSd820a Firmware Version-
   QualcommSd820a Version-
QualcommSd835 Firmware Version-
   QualcommSd835 Version-
QualcommSd845 Firmware Version-
   QualcommSd845 Version-
QualcommSd850 Firmware Version-
   QualcommSd850 Version-
QualcommSda660 Firmware Version-
   QualcommSda660 Version-
QualcommSdm429 Firmware Version-
   QualcommSdm429 Version-
QualcommSdm439 Firmware Version-
   QualcommSdm439 Version-
QualcommSdm630 Firmware Version-
   QualcommSdm630 Version-
QualcommSdm632 Firmware Version-
   QualcommSdm632 Version-
QualcommSdm636 Firmware Version-
   QualcommSdm636 Version-
QualcommSdm660 Firmware Version-
   QualcommSdm660 Version-
QualcommSdm710 Firmware Version-
   QualcommSdm710 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.175
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 3.3 6.5 2.9
AV:A/AC:L/Au:N/C:N/I:P/A:N
CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.