Vulnerability

CVE-2018-11820

Location: OS
Use of non-time constant memcmp function creates side channel that leaks information and leads to cryptographic issues in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in versions IPQ8074, MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MDM9655, MSM8996AU, QCA8081, QCS605, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 800, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016, SXR1130.

Impact

Severity (Manufact.)

N/A

Severity (NIST)

5.5

Severity (Android)

N/A

Chipsets

33

Devices

1495

Affected Hardware

NameAlso known asManufacturer
MSM8909
Snapdragon 210
Qualcomm
MSM8909AA
Snapdragon 212
Qualcomm
MSM8916
Snapdragon 410
Qualcomm
MSM8929
Snapdragon 415
Qualcomm
MSM8917
Snapdragon 425
Qualcomm
MSM8920
Snapdragon 427
Qualcomm
MSM8937
Snapdragon 430
Qualcomm
MSM8940
Snapdragon 435
Qualcomm
SDM429
Snapdragon 429
Qualcomm
SDM439
Snapdragon 439
Qualcomm
33 of 33 row(s) shown.

Rows per page

Page 1 of 4

Timeline

Introduced (est):
Apr 1, 2013
Reported:
Jan 10, 2018
Advisory Published:
Feb 4, 2019
CVE Published:
Feb 25, 2019
Android Patch Level:
None
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter