Vulnerability Description
The gyroscope on Xiaomi Mi 5s devices allows attackers to cause a denial of service (resonance and false data) via a 20.4 kHz audio signal, aka a MEMS ultrasound attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mi | Mi 5S Firmware | - |
| Mi | Mi 5S | - |
Related Weaknesses (CWE)
References
- https://hackaday.com/2018/07/17/freak-out-your-smartphone-with-ultrasound/ExploitThird Party Advisory
- https://medium.com/%40juliodellaflora/ultrassom-pode-causar-anomalias-no-girosc%
- https://hackaday.com/2018/07/17/freak-out-your-smartphone-with-ultrasound/ExploitThird Party Advisory
- https://medium.com/%40juliodellaflora/ultrassom-pode-causar-anomalias-no-girosc%
FAQ
What is CVE-2018-20823?
CVE-2018-20823 is a vulnerability with a CVSS score of 7.5 (HIGH). The gyroscope on Xiaomi Mi 5s devices allows attackers to cause a denial of service (resonance and false data) via a 20.4 kHz audio signal, aka a MEMS ultrasound attack.
How severe is CVE-2018-20823?
CVE-2018-20823 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20823?
Check the references section above for vendor advisories and patch information. Affected products include: Mi Mi 5S Firmware, Mi Mi 5S.