CVE-2018-13904
Improper input validation in SCM handler to access storage in TZ can lead to unauthorized access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9206, MDM9607, MDM9650, MDM9655, QCS605, SD 410/12, SD 675, SD 712 / SD 710 / SD 670, SD 8CX, SXR1130.
Published:Feb 25, 2019
Last Modified:Nov 21, 2024
EPS:Feb 25, 2019
EPSS Score:0.00391
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Qualcomm
Product
Mdm9206
Qualcomm
Mdm9206
Vendor
Qualcomm
Product
Mdm9206 Firmware
Qualcomm
Mdm9206 Firmware
Vendor
Qualcomm
Product
Mdm9607
Qualcomm
Mdm9607
Vendor
Qualcomm
Product
Mdm9607 Firmware
Qualcomm
Mdm9607 Firmware
Vendor
Qualcomm
Product
Mdm9650
Qualcomm
Mdm9650
Vendor
Qualcomm
Product
Mdm9650 Firmware
Qualcomm
Mdm9650 Firmware
Vendor
Qualcomm
Product
Mdm9655
Qualcomm
Mdm9655
Vendor
Qualcomm
Product
Mdm9655 Firmware
Qualcomm
Mdm9655 Firmware
Vendor
Qualcomm
Product
Qcs605
Qualcomm
Qcs605
Vendor
Qualcomm
Product
Qcs605 Firmware
Qualcomm
Qcs605 Firmware
Vendor
Qualcomm
Product
Sd 12
Qualcomm
Sd 12
Vendor
Qualcomm
Product
Sd 12 Firmware
Qualcomm
Sd 12 Firmware
Vendor
Qualcomm
Product
Sd 410
Qualcomm
Sd 410
Vendor
Qualcomm
Product
Sd 410 Firmware
Qualcomm
Sd 410 Firmware
Vendor
Qualcomm
Product
Sd 670
Qualcomm
Sd 670
Vendor
Qualcomm
Product
Sd 670 Firmware
Qualcomm
Sd 670 Firmware
Vendor
Qualcomm
Product
Sd 675
Qualcomm
Sd 675
Vendor
Qualcomm
Product
Sd 675 Firmware
Qualcomm
Sd 675 Firmware
Vendor
Qualcomm
Product
Sd 710
Qualcomm
Sd 710
Vendor
Qualcomm
Product
Sd 710 Firmware
Qualcomm
Sd 710 Firmware
Vendor
Qualcomm
Product
Sd 712
Qualcomm
Sd 712
Vendor
Qualcomm
Product
Sd 712 Firmware
Qualcomm
Sd 712 Firmware
Vendor
Qualcomm
Product
Sd 8cx
Qualcomm
Sd 8cx
Vendor
Qualcomm
Product
Sd 8cx Firmware
Qualcomm
Sd 8cx Firmware
Vendor
Qualcomm
Product
Sxr1130
Qualcomm
Sxr1130
Vendor
Qualcomm
Product
Sxr1130 Firmware
Qualcomm
Sxr1130 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
