PT-2020-9447 · Qualcomm · Qcm2150+48

Published

2020-04-16

·

Updated

2020-04-22

·

CVE-2019-14021

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Snapdragon Auto versions prior to the fixed version Snapdragon Compute versions prior to the fixed version Snapdragon Consumer IOT versions prior to the fixed version Snapdragon Industrial IOT versions prior to the fixed version Snapdragon Mobile versions prior to the fixed version Snapdragon Wearables versions prior to the fixed version APQ8096AU version prior to the fixed version APQ8098 version prior to the fixed version MDM9150 version prior to the fixed version MDM9206 version prior to the fixed version MDM9607 version prior to the fixed version MDM9640 version prior to the fixed version MDM9650 version prior to the fixed version MSM8905 version prior to the fixed version MSM8909 version prior to the fixed version MSM8909W version prior to the fixed version MSM8917 version prior to the fixed version MSM8920 version prior to the fixed version MSM8937 version prior to the fixed version MSM8940 version prior to the fixed version MSM8953 version prior to the fixed version MSM8996AU version prior to the fixed version MSM8998 version prior to the fixed version Nicobar version prior to the fixed version QCM2150 version prior to the fixed version QCS605 version prior to the fixed version QM215 version prior to the fixed version Rennell version prior to the fixed version SC7180 version prior to the fixed version SC8180X version prior to the fixed version SDA660 version prior to the fixed version SDA845 version prior to the fixed version SDM429 version prior to the fixed version SDM429W version prior to the fixed version SDM439 version prior to the fixed version SDM450 version prior to the fixed version SDM630 version prior to the fixed version SDM632 version prior to the fixed version SDM636 version prior to the fixed version SDM660 version prior to the fixed version SDM670 version prior to the fixed version SDM710 version prior to the fixed version SDM845 version prior to the fixed version SDM850 version prior to the fixed version SDX20 version prior to the fixed version SDX24 version prior to the fixed version SDX55 version prior to the fixed version SM6150 version prior to the fixed version SM7150 version prior to the fixed version SM8150 version prior to the fixed version SXR1130 version prior to the fixed version
Description: A possible buffer overrun occurs when processing EFS filename and payload sent over the diag interface due to a lack of check for filename length and payload size received. This issue affects various Snapdragon products, including Auto, Compute, Consumer IOT, Industrial IOT, Mobile, and Wearables, as well as specific chipsets.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14021

Affected Products

Apq8096Au
Apq8098
Mdm9150
Mdm9206
Mdm9607
Mdm9640
Mdm9650
Msm8905
Msm8909W
Msm8917
Msm8920
Msm8937
Msm8940
Msm8953
Msm8996Au
Msm8998
Nicobar
Qcm2150
Qcs605
Qm215
Rennell
Sc7180
Sc8180X
Sda660
Sda845
Sdm429
Sdm439
Sdm450
Sdm630
Sdm632
Sdm636
Sdm660
Sdm670
Sdm710
Sdm845
Sdm850
Sdx20
Sdx24
Sdx55
Sm6150
Sm7150
Sm8150
Sxr1130
Snapdragon Auto
Snapdragon Compute
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Mobile
Snapdragon Wearables