60
CVE-2019-10538
—CVSS 3.1
9.8 critical
EPSS
1%p64
Published
()
Modified
Description
Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address range which can compromise HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM660, SDX20, SDX24
- Vendors
- qualcomm
- Products
- msm8909w firmware, msm8996au firmware, qcs405 firmware, qcs605 firmware, qualcomm 215 firmware, sd 425 firmware, sd 439 firmware, sd 429 firmware, sd 450 firmware, sd 625 firmware, sd 632 firmware, sd 636 firmware
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H