PT-2019-11940 · Qualcomm · Sda660+38

Published

2019-12-18

·

Updated

2021-07-21

·

CVE-2019-10595

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon versions (affected versions not specified)
Description The issue is related to a possible buffer overwrite in the message handler due to a lack of validation of the tid value calculated from packets received from firmware. This affects various Qualcomm Snapdragon products, including Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, and Snapdragon Wired Infrastructure and Networking, in multiple chipsets such as APQ8009, APQ8053, APQ8064, APQ8096AU, IPQ4019, IPQ8064, MDM9206, MDM9207C, MDM9607, MDM9615, MDM9640, MDM9650, MSM8909, MSM8909W, MSM8939, MSM8996AU, QCA4531, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCA9558, QCA9880, QCA9886, QCA9980, SDA660, SDM630, SDM636, SDM660, SDX20, and SDX24.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10595

Affected Products

Apq8009
Apq8053
Apq8064
Apq8096Au
Ipq4019
Ipq8064
Mdm9206
Mdm9207C
Mdm9607
Mdm9615
Mdm9640
Mdm9650
Msm8909W
Msm8939
Msm8996Au
Qca4531
Qca6174A
Qca6574Au
Qca9377
Qca9379
Qca9558
Qca9880
Qca9886
Qca9980
Sda660
Sdm630
Sdm636
Sdm660
Sdx20
Sdx24
Snapdragon Auto
Snapdragon Consumer Electronics Connectivity
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Iot
Snapdragon Mobile
Snapdragon Voice & Music
Snapdragon Wearables
Snapdragon Wired Infrastructure/Networking