MEDIUM · 5.5

CVE-2018-12005

An unprivileged user can issue a binder call and cause a system halt in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & M...

Vulnerability Description

An unprivileged user can issue a binder call and cause a system halt in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24, SM7150

CVSS Score

5.5

MEDIUM

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
QualcommMdm9150 Firmware-
QualcommMdm9150-
QualcommMdm9206 Firmware-
QualcommMdm9206-
QualcommMdm9607 Firmware-
QualcommMdm9607-
QualcommMdm9640 Firmware-
QualcommMdm9640-
QualcommMdm9650 Firmware-
QualcommMdm9650-
QualcommMsm8909W Firmware-
QualcommMsm8909W-
QualcommMsm8996Au Firmware-
QualcommMsm8996Au-
QualcommQcs605 Firmware-
QualcommQcs605-
QualcommQm215 Firmware-
QualcommQm215-
QualcommSd 210 Firmware-
QualcommSd 210-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-12005?

CVE-2018-12005 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An unprivileged user can issue a binder call and cause a system halt in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & M...

How severe is CVE-2018-12005?

CVE-2018-12005 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-12005?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Mdm9150 Firmware, Qualcomm Mdm9150, Qualcomm Mdm9206 Firmware, Qualcomm Mdm9206, Qualcomm Mdm9607 Firmware.