| Summary | Lack of check on out of range of bssid parameter When processing scan start command will lead to buffer flow in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9886, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM630, SDM632, SDM636, SDM660, SDM710, SDX20, Snapdragon_High_Med_2016 |
|---|---|
| Publication Date | Oct. 26, 2018, 10:29 p.m. |
| Registration Date | March 1, 2021, 6:47 p.m. |
| Last Update | Nov. 21, 2024, 12:44 p.m. |
| CVSS3.0 : HIGH | |
| スコア | 7.8 |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 攻撃元区分(AV) | ローカル |
| 攻撃条件の複雑さ(AC) | 低 |
| 攻撃に必要な特権レベル(PR) | 低 |
| 利用者の関与(UI) | 不要 |
| 影響の想定範囲(S) | 変更なし |
| 機密性への影響(C) | 高 |
| 完全性への影響(I) | 高 |
| 可用性への影響(A) | 高 |
| CVSS2.0 : HIGH | |
| Score | 7.2 |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| 攻撃元区分(AV) | ローカル |
| 攻撃条件の複雑さ(AC) | 低 |
| 攻撃前の認証要否(Au) | 不要 |
| 機密性への影響(C) | 高 |
| 完全性への影響(I) | 高 |
| 可用性への影響(A) | 高 |
| Get all privileges. | いいえ |
| Get user privileges | いいえ |
| Get other privileges | いいえ |
| User operation required | いいえ |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:ipq8074_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:ipq8074:-:*:*:*:*:*:*:* | ||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:mdm9206:-:*:*:*:*:*:*:* | ||||
| Configuration3 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:mdm9607:-:*:*:*:*:*:*:* | ||||
| Configuration4 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:mdm9635m_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:mdm9635m:-:*:*:*:*:*:*:* | ||||
| Configuration5 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:mdm9640_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:mdm9640:-:*:*:*:*:*:*:* | ||||
| Configuration6 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:mdm9650_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:mdm9650:-:*:*:*:*:*:*:* | ||||
| Configuration7 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:msm8996au_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:msm8996au:-:*:*:*:*:*:*:* | ||||
| Configuration8 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:qca4531_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:qca4531:-:*:*:*:*:*:*:* | ||||
| Configuration9 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:qca6174a_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:qca6174a:-:*:*:*:*:*:*:* | ||||
| Configuration10 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:qca6564_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:qca6564:-:*:*:*:*:*:*:* | ||||
| Configuration11 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:qca6574_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:qca6574:-:*:*:*:*:*:*:* | ||||
| Configuration12 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:qca6574au:-:*:*:*:*:*:*:* | ||||
| Configuration13 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:qca6584_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:qca6584:-:*:*:*:*:*:*:* | ||||
| Configuration14 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:qca6584au_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:qca6584au:-:*:*:*:*:*:*:* | ||||
| Configuration15 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:qca9377_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:qca9377:-:*:*:*:*:*:*:* | ||||
| Configuration16 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:qca9378_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:qca9378:-:*:*:*:*:*:*:* | ||||
| Configuration17 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:qca9379_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:qca9379:-:*:*:*:*:*:*:* | ||||
| Configuration18 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:qca9886_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:qca9886:-:*:*:*:*:*:*:* | ||||
| Configuration19 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_210_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_210:-:*:*:*:*:*:*:* | ||||
| Configuration20 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_212_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_212:-:*:*:*:*:*:*:* | ||||
| Configuration21 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_205_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_205:-:*:*:*:*:*:*:* | ||||
| Configuration22 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_425_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_425:-:*:*:*:*:*:*:* | ||||
| Configuration23 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_427_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_427:-:*:*:*:*:*:*:* | ||||
| Configuration24 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_430_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_430:-:*:*:*:*:*:*:* | ||||
| Configuration25 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_435_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_435:-:*:*:*:*:*:*:* | ||||
| Configuration26 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_450_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_450:-:*:*:*:*:*:*:* | ||||
| Configuration27 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_600_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_600:-:*:*:*:*:*:*:* | ||||
| Configuration28 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_625_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_625:-:*:*:*:*:*:*:* | ||||
| Configuration29 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_650_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_650:-:*:*:*:*:*:*:* | ||||
| Configuration30 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_652_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_652:-:*:*:*:*:*:*:* | ||||
| Configuration31 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_810_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_810:-:*:*:*:*:*:*:* | ||||
| Configuration32 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_820_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_820:-:*:*:*:*:*:*:* | ||||
| Configuration33 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_820a_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_820a:-:*:*:*:*:*:*:* | ||||
| Configuration34 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_835_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_835:-:*:*:*:*:*:*:* | ||||
| Configuration35 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_845_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_845:-:*:*:*:*:*:*:* | ||||
| Configuration36 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sd_850_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sd_850:-:*:*:*:*:*:*:* | ||||
| Configuration37 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sda660_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sda660:-:*:*:*:*:*:*:* | ||||
| Configuration38 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sdm630_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sdm630:-:*:*:*:*:*:*:* | ||||
| Configuration39 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sdm632_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sdm632:-:*:*:*:*:*:*:* | ||||
| Configuration40 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sdm636_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sdm636:-:*:*:*:*:*:*:* | ||||
| Configuration41 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sdm660_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sdm660:-:*:*:*:*:*:*:* | ||||
| Configuration42 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sdm710_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sdm710:-:*:*:*:*:*:*:* | ||||
| Configuration43 | or higher | or less | more than | less than | |
| cpe:2.3:o:qualcomm:sdx20_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:qualcomm:sdx20:-:*:*:*:*:*:*:* | ||||
| Title | 複数の Snapdragon 製品におけるバッファエラーの脆弱性 |
|---|---|
| Summary | Snapdragon Automobile、Snapdragon Mobile、Snapdragon Wear には、バッファエラーの脆弱性が存在します。 |
| Possible impacts | 情報を取得される、情報を改ざんされる、およびサービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | July 2, 2018, midnight |
| Registration Date | Jan. 16, 2019, 3:29 p.m. |
| Last Update | Jan. 16, 2019, 3:29 p.m. |
| クアルコム |
| IPQ8074 ファームウェア |
| MDM9206 ファームウェア |
| MDM9607 ファームウェア |
| MDM9635M ファームウェア |
| MDM9640 ファームウェア |
| MDM9650 ファームウェア |
| MSM8996AU ファームウェア |
| QCA4531 ファームウェア |
| QCA6174A ファームウェア |
| QCA6564 ファームウェア |
| QCA6574 ファームウェア |
| QCA6574AU ファームウェア |
| QCA6584 ファームウェア |
| QCA6584AU ファームウェア |
| QCA9377 ファームウェア |
| QCA9378 ファームウェア |
| QCA9379 ファームウェア |
| QCA9886 ファームウェア |
| SD 205 ファームウェア |
| SD 210 ファームウェア |
| SD 212 ファームウェア |
| SD 425 ファームウェア |
| SD 427 ファームウェア |
| SD 430 ファームウェア |
| SD 435 ファームウェア |
| SD 450 ファームウェア |
| SD 600 ファームウェア |
| SD 625 ファームウェア |
| SD 650 ファームウェア |
| SD 652 ファームウェア |
| SD 810 ファームウェア |
| SD 820 ファームウェア |
| SD 820A ファームウェア |
| SD 835 ファームウェア |
| SD 845 ファームウェア |
| SD 850 ファームウェア |
| SDA 660 ファームウェア |
| SDM 630 ファームウェア |
| SDM 632 ファームウェア |
| SDM 636 ファームウェア |
| SDM 660 ファームウェア |
| SDM710 ファームウェア |
| SDX20 ファームウェア |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2019年01月16日] 掲載 |
Jan. 16, 2019, 3:29 p.m. |