ZeroHour

CVE-2019-10625

CVSS 3.1
7.1 high
EPSS
<1%p8
Published
()
Modified
Description

Out of bound access in diag services when DCI command buffer reallocation is not done properly with required capacity in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8096AU, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, QCS605, Rennell, SC8180X, SDM429W, SDM710, SDX55, SM7150, SM8150

Vendors
qualcomm
Products
apq8009 firmware, apq8096au firmware, mdm9206 firmware, mdm9207c firmware, mdm9607 firmware, mdm9640 firmware, mdm9650 firmware, qcs605 firmware, rennell firmware, sc8180x firmware, sdm429w firmware, sdm710 firmware
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.