PT-2020-9062 · Qualcomm · Snapdragon Wearables+6
Published
2020-04-16
·
Updated
2020-04-27
·
CVE-2019-10523
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Snapdragon Auto versions APQ8009 through SM8250
Snapdragon Compute versions APQ8009 through SM8250
Snapdragon Consumer IOT versions APQ8009 through SM8250
Snapdragon Industrial IOT versions APQ8009 through SM8250
Snapdragon IoT versions APQ8009 through SM8250
Snapdragon Mobile versions APQ8009 through SM8250
Snapdragon Wearables versions APQ8009 through SM8250
Description
Target specific data is being sent to a remote server, leading to information exposure. This issue affects various Snapdragon products, including Auto, Compute, Consumer IOT, Industrial IOT, IoT, Mobile, and Wearables.
Recommendations
For Snapdragon Auto versions APQ8009 through SM8250, restrict access to sensitive data to minimize the risk of exploitation.
For Snapdragon Compute versions APQ8009 through SM8250, consider disabling remote server connections until a fix is available.
For Snapdragon Consumer IOT versions APQ8009 through SM8250, avoid sending target specific data to remote servers.
For Snapdragon Industrial IOT versions APQ8009 through SM8250, implement additional security measures to protect sensitive information.
For Snapdragon IoT versions APQ8009 through SM8250, restrict access to vulnerable components.
For Snapdragon Mobile versions APQ8009 through SM8250, consider updating to a newer version that addresses the issue.
For Snapdragon Wearables versions APQ8009 through SM8250, disable remote server connections as a temporary workaround.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snapdragon Auto
Snapdragon Compute
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Iot
Snapdragon Mobile
Snapdragon Wearables