ZeroHour

CVE-2019-10562

CVSS 3.1
7.8 high
EPSS
<1%p5
Published
()
Modified
Description

u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug policies to be loaded into secure memory and leads to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ6018, Kamorta, MSM8998, Nicobar, QCS404, QCS605, QCS610, Rennell, SA415M, SA6155P, SC7180, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

Vendors
qualcomm
Products
ipq6018 firmware, kamorta firmware, msm8998 firmware, nicobar firmware, qcs404 firmware, qcs605 firmware, qcs610 firmware, rennell firmware, sa415m firmware, sa6155p firmware, sc7180 firmware, sda660 firmware
Weakness
CWE-287, CWE-347
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.