CVE-2016-10428
—CVSS 3.0
7.5 high
EPSS
<1%p56
Published
()
Modified
Description
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, HMAC verification in counter file uses an insecure memcmp which may assist a timing attack.
- Vendors
- qualcomm
- Products
- sd 425 firmware, sd 430 firmware, sd 450 firmware, sd 625 firmware, sd 650 firmware, sd 652 firmware, sd 820 firmware, sd 820a firmware
- Weakness
- CWE-200
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.