Description
In Snapdragon (Automobile, Mobile, Wear) in version MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SDA660, the com.qualcomm.embms is a vendor package deployed in the system image which has an inadequate permission level and allows any application installed from Play Store to request this permission at install-time. The system application interfaces with the Radio Interface Layer leading to potential access control issue.
Published: 2018-09-20
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-3317 In Snapdragon (Automobile, Mobile, Wear) in version MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SDA660, the com.qualcomm.embms is a vendor package deployed in the system image which has an inadequate permission level and allows any application installed from Play Store to request this permission at install-time. The system application interfaces with the Radio Interface Layer leading to potential access control issue.
History

No history.

Subscriptions

Qualcomm Msm8909w Msm8909w Firmware Msm8996au Msm8996au Firmware Sd205 Sd205 Firmware Sd210 Sd210 Firmware Sd212 Sd212 Firmware Sd415 Sd415 Firmware Sd430 Sd430 Firmware Sd450 Sd450 Firmware Sd615 Sd615 Firmware Sd616 Sd616 Firmware Sd617 Sd617 Firmware Sd625 Sd625 Firmware Sd650 Sd650 Firmware Sd652 Sd652 Firmware Sd810 Sd810 Firmware Sd820 Sd820 Firmware Sd820a Sd820a Firmware Sd835 Sd835 Firmware Sd845 Sd845 Firmware Sda660 Sda660 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2024-08-05T08:01:52.986Z

Reserved: 2018-05-18T00:00:00.000Z

Link: CVE-2018-11277

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-09-20T13:29:01.167

Modified: 2024-11-21T03:43:02.667

Link: CVE-2018-11277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses