PT-2020-9062 · Qualcomm · Snapdragon Wearables+6

Published

2020-04-16

·

Updated

2020-04-27

·

CVE-2019-10523

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Snapdragon Auto versions APQ8009 through SM8250 Snapdragon Compute versions APQ8009 through SM8250 Snapdragon Consumer IOT versions APQ8009 through SM8250 Snapdragon Industrial IOT versions APQ8009 through SM8250 Snapdragon IoT versions APQ8009 through SM8250 Snapdragon Mobile versions APQ8009 through SM8250 Snapdragon Wearables versions APQ8009 through SM8250
Description Target specific data is being sent to a remote server, leading to information exposure. This issue affects various Snapdragon products, including Auto, Compute, Consumer IOT, Industrial IOT, IoT, Mobile, and Wearables.
Recommendations For Snapdragon Auto versions APQ8009 through SM8250, restrict access to sensitive data to minimize the risk of exploitation. For Snapdragon Compute versions APQ8009 through SM8250, consider disabling remote server connections until a fix is available. For Snapdragon Consumer IOT versions APQ8009 through SM8250, avoid sending target specific data to remote servers. For Snapdragon Industrial IOT versions APQ8009 through SM8250, implement additional security measures to protect sensitive information. For Snapdragon IoT versions APQ8009 through SM8250, restrict access to vulnerable components. For Snapdragon Mobile versions APQ8009 through SM8250, consider updating to a newer version that addresses the issue. For Snapdragon Wearables versions APQ8009 through SM8250, disable remote server connections as a temporary workaround.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10523

Affected Products

Snapdragon Auto
Snapdragon Compute
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Iot
Snapdragon Mobile
Snapdragon Wearables