PT-2019-16369 · Qualcomm · Ipq4019+30

Published

2019-07-25

·

Updated

2020-08-24

·

CVE-2019-2301

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon Auto versions (affected versions not specified) Qualcomm Snapdragon Compute versions (affected versions not specified) Qualcomm Snapdragon Consumer IOT versions (affected versions not specified) Qualcomm Snapdragon Industrial IOT versions (affected versions not specified) Qualcomm Snapdragon Mobile versions (affected versions not specified) Qualcomm Snapdragon Wearables versions (affected versions not specified) Qualcomm Snapdragon Wired Infrastructure and Networking versions (affected versions not specified) Qualcomm IPQ4019 versions (affected versions not specified) Qualcomm IPQ8064 versions (affected versions not specified) Qualcomm MSM8909W versions (affected versions not specified) Qualcomm MSM8996AU versions (affected versions not specified) Qualcomm QCA9980 versions (affected versions not specified) Qualcomm QCS605 versions (affected versions not specified) Qualcomm 215 versions (affected versions not specified) Qualcomm SD 425 versions (affected versions not specified) Qualcomm SD 439 / SD 429 versions (affected versions not specified) Qualcomm SD 450 versions (affected versions not specified) Qualcomm SD 625 versions (affected versions not specified) Qualcomm SD 632 versions (affected versions not specified) Qualcomm SD 636 versions (affected versions not specified) Qualcomm SD 712 / SD 710 / SD 670 versions (affected versions not specified) Qualcomm SD 820A versions (affected versions not specified) Qualcomm SD 845 / SD 850 versions (affected versions not specified) Qualcomm SD 855 versions (affected versions not specified) Qualcomm SDM439 versions (affected versions not specified) Qualcomm SDM660 versions (affected versions not specified) Qualcomm SDX24 versions (affected versions not specified)
Description The issue is related to the possibility of an out-of-bound read if the id received from SPI is not in the range of FIFO. This affects various Qualcomm Snapdragon products and chipsets, including Auto, Compute, Consumer IOT, Industrial IOT, Mobile, Wearables, Wired Infrastructure and Networking, as well as specific chipsets like IPQ4019, IPQ8064, MSM8909W, and others.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-2301

Affected Products

Ipq4019
Ipq8064
Msm8909W
Msm8996Au
Qca9980
Qcs605
Sd 215
Sd 425
Sd 429
Sd 439
Sd 450
Sd 625
Sd 632
Sd 636
Sd 670
Sd 710
Sd 712
Sd 820A
Sd 845
Sd 850
Sd 855
Sdm439
Sdm660
Sdx24
Snapdragon Auto
Snapdragon Compute
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Mobile
Snapdragon Wearables
Snapdragon Wired Infrastructure/Networking