PT-2020-9104 · Qualcomm · Snapdragon Connectivity+10
Published
2020-04-16
·
Updated
2020-08-24
·
CVE-2019-10608
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Qualcomm Snapdragon versions (affected versions not specified)
Description
An information disclosure issue occurs due to the lack of binding between the secure keypad session and the secure display session. This allows a user to take control of the REE, stop the secure keypad session, and read the keypad input. The issue affects various Snapdragon products, including Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, and Snapdragon Wired Infrastructure and Networking, in specific chipsets such as APQ8009, MSM8905, and MSM8909.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apq8009
Msm8905
Msm8909W
Snapdragon Auto
Snapdragon Compute
Snapdragon Connectivity
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Mobile
Snapdragon Voice & Music
Snapdragon Wired Infrastructure/Networking