7.8
HIGH
CVE-2018-11292
Snapdragon WLAN Command Handler Integer and Heap Overflows
Description

In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCA6574AU, QCA6584, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820A, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016, lack of input validation in WLANWMI command handlers can lead to integer & heap overflows.

INFO

Published Date :

Sept. 20, 2018, 1:29 p.m.

Last Modified :

Nov. 21, 2024, 3:43 a.m.

Remotely Exploitable :

No

Impact Score :

5.9

Exploitability Score :

1.8
Public PoC/Exploit Available at Github

CVE-2018-11292 has a 1 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

Affected Products

The following products are affected by CVE-2018-11292 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Qualcomm qca6574au_firmware
2 Qualcomm sdm660_firmware
3 Qualcomm msm8996au_firmware
4 Qualcomm mdm9650_firmware
5 Qualcomm msm8909w_firmware
6 Qualcomm sd210_firmware
7 Qualcomm sd625_firmware
8 Qualcomm sd205_firmware
9 Qualcomm mdm9206_firmware
10 Qualcomm mdm9607_firmware
11 Qualcomm mdm9640_firmware
12 Qualcomm qca6584_firmware
13 Qualcomm sdm630_firmware
14 Qualcomm sd450_firmware
15 Qualcomm sd212_firmware
16 Qualcomm sd425_firmware
17 Qualcomm sd427_firmware
18 Qualcomm sd430_firmware
19 Qualcomm sd650_firmware
20 Qualcomm sd652_firmware
21 Qualcomm sd820a_firmware
22 Qualcomm sdm429_firmware
23 Qualcomm sdm439_firmware
24 Qualcomm sdm632_firmware
25 Qualcomm sdm636_firmware
26 Qualcomm sd410_firmware
27 Qualcomm sd412_firmware
28 Qualcomm sd615_firmware
29 Qualcomm sd616_firmware
30 Qualcomm sd415_firmware
31 Qualcomm mdm9206
32 Qualcomm mdm9607
33 Qualcomm mdm9640
34 Qualcomm mdm9650
35 Qualcomm msm8909w
36 Qualcomm msm8996au
37 Qualcomm qca6574au
38 Qualcomm qca6584
39 Qualcomm sd205
40 Qualcomm sd210
41 Qualcomm sd450
42 Qualcomm sdm630
43 Qualcomm sdm429
44 Qualcomm sdm439
45 Qualcomm sdm632
46 Qualcomm sdm636
47 Qualcomm sdm660
48 Qualcomm sd625
49 Qualcomm sd212
50 Qualcomm sd425
51 Qualcomm sd427
52 Qualcomm sd430
53 Qualcomm sd650
54 Qualcomm sd652
55 Qualcomm sd820a
56 Qualcomm sd410
57 Qualcomm sd412
58 Qualcomm sd615
59 Qualcomm sd616
60 Qualcomm sd415
References to Advisories, Solutions, and Tools

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Samsung security patch description

Updated: 6 years, 2 months ago
0 stars 0 fork 0 watcher
Born at : Oct. 14, 2018, 12:38 p.m. This repo has been linked 458 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2018-11292 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2018-11292 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Nov. 21, 2024

    Action Type Old Value New Value
    Added Reference http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000051618
    Added Reference https://source.android.com/security/bulletin/2018-09-01#qualcomm-closed-source-components
    Added Reference https://www.qualcomm.com/company/product-security/bulletins
  • CVE Modified by [email protected]

    May. 14, 2024

    Action Type Old Value New Value
  • CWE Remap by [email protected]

    Aug. 24, 2020

    Action Type Old Value New Value
    Changed CWE CWE-119 CWE-787 CWE-190
  • Initial Analysis by [email protected]

    Nov. 23, 2018

    Action Type Old Value New Value
    Added CVSS V2 (AV:L/AC:L/Au:N/C:C/I:C/A:C)
    Added CVSS V3 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Changed Reference Type https://www.qualcomm.com/company/product-security/bulletins No Types Assigned https://www.qualcomm.com/company/product-security/bulletins Vendor Advisory
    Changed Reference Type http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000051618 No Types Assigned http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000051618 Third Party Advisory
    Changed Reference Type https://source.android.com/security/bulletin/2018-09-01#qualcomm-closed-source-components No Types Assigned https://source.android.com/security/bulletin/2018-09-01#qualcomm-closed-source-components Third Party Advisory
    Added CWE CWE-119
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:mdm9206:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:mdm9607:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:mdm9640_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:mdm9640:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:mdm9650_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:mdm9650:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:msm8909w_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:msm8909w:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:msm8996au_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:msm8996au:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qca6574au:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qca6584_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qca6584:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd210_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd210:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd212_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd212:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd205_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd205:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd410_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd410:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd412_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd412:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd425_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd425:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd427_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd427:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd430_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd430:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd450_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd450:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd615_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd615:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd616_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd616:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd415_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd415:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd625_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd625:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd650_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd650:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd652_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd652:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sd820a_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sd820a:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sdm429_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sdm429:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sdm439_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sdm439:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sdm630_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sdm630:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sdm632_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sdm632:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sdm636_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sdm636:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:sdm660_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:sdm660:-:*:*:*:*:*:*:*
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2018-11292 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2018-11292 weaknesses.

Exploit Prediction

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.

0.05 }} 0.01%

score

0.18557

percentile

CVSS30 - Vulnerability Scoring System
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability