PT-2020-9449 · Qualcomm · Snapdragon Industrial Iot+14

Published

2020-01-21

·

Updated

2020-01-24

·

CVE-2019-14023

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Qualcomm Snapdragon versions (affected versions not specified)
Description: A string format issue occurs due to the lack of user input validation, which fails to ensure that inputs are properly NULL terminated before string copy. This issue affects various Qualcomm Snapdragon products, including Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, and Snapdragon Voice & Music, in specific chipsets such as MDM9607, Nicobar, Rennell, SA6155P, SDX55, SM6150, SM7150, SM8150, SM8250, and SXR2130.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-14023

Affected Products

Mdm9607
Nicobar
Rennell
Sa6155P
Sdx55
Sm6150
Sm7150
Sm8150
Sm8250
Sxr2130
Snapdragon Auto
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Mobile
Snapdragon Voice & Music