CVE-2018-11922
Critical
Published: 26 November 2024
Published
26 November 2024
Modified
09 January 2025
KEV Added
—
Patch
—
CVSS Score v3.1
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.0017
37.8th percentile
Risk Priority
20
60% EPSS · 20% KEV · 20% CVSS
Summary
CVE-2018-11922 is a critical-severity an unspecified weakness vulnerability in Qualcomm Mdm9206 Firmware. Its CVSS base score is 9.8 (Critical).
Operationally, ranked at the 37.8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2018-3914
Vulnerability details
Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
qualcomm
mdm9206 firmware
all versions
qualcomm
mdm9607 firmware
all versions
qualcomm
mdm9640 firmware
all versions
qualcomm
mdm9650 firmware
all versions
qualcomm
215 firmware
all versions
qualcomm
sd 210 firmware
all versions
qualcomm
sd 212 firmware
all versions
qualcomm
sd 205 firmware
all versions
qualcomm
sd 425 firmware
all versions
qualcomm
sd 427 firmware
all versions
+12 more product configuration(s) — see NVD for full list
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.