CVE-2018-11993 describes a buffer overflow vulnerability in Qualcomm Snapdragon Wear MDM9206 and MDM9607 versions, stemming from an improper check during MQTT connection requests. This high-severity vulnerability (CVSS 8.8) is network-adjacent, low complexity, and requires no user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. While the EPSS score is low and there is no evidence of active exploitation, public exploit code, or significant community discussion, affected organizations should still prioritize patching due to the critical impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.