ZeroHour

CVE-2016-10428

CVSS 3.0
7.5 high
EPSS
<1%p56
Published
()
Modified
Description

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, HMAC verification in counter file uses an insecure memcmp which may assist a timing attack.

Vendors
qualcomm
Products
sd 425 firmware, sd 430 firmware, sd 450 firmware, sd 625 firmware, sd 650 firmware, sd 652 firmware, sd 820 firmware, sd 820a firmware
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.