Vulnerability

CVE-2018-5383

Component: BLUETOOTH
Location: FIRMWARE
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.

Impact

Severity (Manufact.)

HIGH

Severity (NIST)

6.8

Severity (Android)

N/A

Chipsets

29

Devices

1478

Affected Hardware

NameAlso known asManufacturer
MSM8909
Snapdragon 210
Qualcomm
MSM8909AA
Snapdragon 212
Qualcomm
MSM8916
Snapdragon 410
Qualcomm
MSM8929
Snapdragon 415
Qualcomm
MSM8917
Snapdragon 425
Qualcomm
MSM8920
Snapdragon 427
Qualcomm
MSM8937
Snapdragon 430
Qualcomm
MSM8940
Snapdragon 435
Qualcomm
SDM429
Snapdragon 429
Qualcomm
SDM439
Snapdragon 439
Qualcomm
29 of 29 row(s) shown.

Rows per page

Page 1 of 3

Timeline

Introduced (est):
Jan 1, 2014
Reported:
Jan 18, 2018
Advisory Published:
Apr 1, 2024
CVE Published:
Aug 7, 2018
Android Patch Level:
Aug 2018
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter