PT-2020-9481 · Qualcomm · Sdm710+20

Published

2020-06-02

·

Updated

2020-06-03

·

CVE-2019-14054

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Snapdragon Compute versions prior to the fixed version Snapdragon Consumer IOT versions prior to the fixed version Snapdragon Industrial IOT versions prior to the fixed version Snapdragon Mobile versions prior to the fixed version Snapdragon Wired Infrastructure and Networking versions prior to the fixed version Kamorta versions prior to the fixed version MSM8998 versions prior to the fixed version QCS404 versions prior to the fixed version QCS605 versions prior to the fixed version SDA660 versions prior to the fixed version SDA845 versions prior to the fixed version SDM630 versions prior to the fixed version SDM636 versions prior to the fixed version SDM660 versions prior to the fixed version SDM670 versions prior to the fixed version SDM710 versions prior to the fixed version SDM845 versions prior to the fixed version SDM850 versions prior to the fixed version SM8150 versions prior to the fixed version SXR1130 versions prior to the fixed version SXR2130 versions prior to the fixed version
Description: The issue is related to improper permissions in the XBL SEC region, which allows a user to update XBL SEC code and data. This can also divert the RAM dump path to the normal cold boot path.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-14054

Affected Products

Kamorta
Msm8998
Qcs404
Qcs605
Sda660
Sda845
Sdm630
Sdm636
Sdm660
Sdm670
Sdm710
Sdm845
Sdm850
Sm8150
Sxr1130
Sxr2130
Snapdragon Compute
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Mobile
Snapdragon Wired Infrastructure/Networking