PT-2019-16338 · Qualcomm · Sd 16+56

Published

2019-11-06

·

Updated

2021-07-21

·

CVE-2019-2258

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon Auto versions MDM9150 through MDM9655 Qualcomm Snapdragon Compute versions MDM9150 through MDM9655 Qualcomm Snapdragon Consumer IOT versions MDM9150 through MDM9655 Qualcomm Snapdragon Industrial IOT versions MDM9150 through MDM9655 Qualcomm Snapdragon IoT versions MDM9150 through MDM9655 Qualcomm Snapdragon Mobile versions MDM9150 through MDM9655 Qualcomm Snapdragon Voice & Music versions MDM9150 through MDM9655 Qualcomm Snapdragon Wearables versions MDM9150 through MDM9655 Qualcomm MDM9150 Qualcomm MDM9607 Qualcomm MDM9615 Qualcomm MDM9625 Qualcomm MDM9635M Qualcomm MDM9640 Qualcomm MDM9650 Qualcomm MDM9655 Qualcomm MSM8909W Qualcomm MSM8996AU Qualcomm QCS605 Qualcomm 215 Qualcomm SD 210 Qualcomm SD 212 Qualcomm SD 205 Qualcomm SD 425 Qualcomm SD 427 Qualcomm SD 430 Qualcomm SD 435 Qualcomm SD 439 Qualcomm SD 429 Qualcomm SD 450 Qualcomm SD 615 Qualcomm SD 16 Qualcomm SD 415 Qualcomm SD 625 Qualcomm SD 632 Qualcomm SD 636 Qualcomm SD 650 Qualcomm SD 52 Qualcomm SD 665 Qualcomm SD 675 Qualcomm SD 712 Qualcomm SD 710 Qualcomm SD 670 Qualcomm SD 730 Qualcomm SD 820 Qualcomm SD 820A Qualcomm SD 835 Qualcomm SD 845 Qualcomm SD 850 Qualcomm SD 855 Qualcomm SD 8CX Qualcomm SDA660 Qualcomm SDM439 Qualcomm SDM630 Qualcomm SDM660 Qualcomm SDX20 Qualcomm Snapdragon High Med 2016 Qualcomm SXR1130
Description The issue is caused by improper validation of array index, leading to out-of-bounds write and subsequent memory corruption in MMCP. This affects various Qualcomm Snapdragon products, including Auto, Compute, Consumer IOT, Industrial IOT, IoT, Mobile, Voice & Music, and Wearables, across a range of chipsets.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-2258

Affected Products

215
Mdm9150
Mdm9607
Mdm9615
Mdm9625
Mdm9635M
Mdm9640
Mdm9650
Mdm9655
Msm8909W
Msm8996Au
Qcs605
Sd 16
Sd 205
Sd 210
Sd 212
Sd 415
Sd 425
Sd 427
Sd 429
Sd 430
Sd 435
Sd 439
Sd 450
Sd 52
Sd 615
Sd 625
Sd 632
Sd 636
Sd 650
Sd 665
Sd 670
Sd 675
Sd 710
Sd 712
Sd 730
Sd 820
Sd 820A
Sd 835
Sd 845
Sd 850
Sd 855
Sd 8Cx
Sda660
Sdm439
Sdm630
Sdm660
Sdx20
Sxr1130
Snapdragon Auto
Snapdragon Compute
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Iot
Snapdragon Mobile
Snapdragon Voice & Music
Snapdragon Wearables