ZeroHour

CVE-2019-14089

CVSS 3.1
7.8 high
EPSS
<1%p5
Published
()
Modified
Description

u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-provisioned after a user data erase or a factory reset' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Kamorta, Nicobar, QCS404, QCS610, Rennell, SA515M, SA6155P, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130

Vendors
qualcomm
Products
kamorta firmware, nicobar firmware, qcs404 firmware, qcs610 firmware, rennell firmware, sa515m firmware, sa6155p firmware, sc7180 firmware, sc8180x firmware, sdx55 firmware, sm6150 firmware, sm7150 firmware
Weakness
CWE-327
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.