PT-2020-9104 · Qualcomm · Snapdragon Connectivity+10

Published

2020-04-16

·

Updated

2020-08-24

·

CVE-2019-10608

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon versions (affected versions not specified)
Description An information disclosure issue occurs due to the lack of binding between the secure keypad session and the secure display session. This allows a user to take control of the REE, stop the secure keypad session, and read the keypad input. The issue affects various Snapdragon products, including Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, and Snapdragon Wired Infrastructure and Networking, in specific chipsets such as APQ8009, MSM8905, and MSM8909.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-10608

Affected Products

Apq8009
Msm8905
Msm8909W
Snapdragon Auto
Snapdragon Compute
Snapdragon Connectivity
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Mobile
Snapdragon Voice & Music
Snapdragon Wired Infrastructure/Networking