ZeroHour

CVE-2019-14047

CVSS 3.1
7.8 high
EPSS
<1%p11
Published
()
Modified
Description

While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to the IPA HW commit list in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8053, APQ8096AU, MDM9607, MSM8909W, MSM8996, MSM8996AU, QCN7605, QCS605, SC8180X, SDA845, SDX20, SDX24, SDX55, SM8150, SXR1130

Vendors
qualcomm
Products
apq8053 firmware, apq8096au firmware, mdm9607 firmware, msm8909w firmware, msm8996 firmware, msm8996au firmware, qcn7605 firmware, qcs605 firmware, sc8180x firmware, sda845 firmware, sdx20 firmware, sdx24 firmware
Weakness
CWE-20
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.