ZeroHour

CVE-2019-2312

CVSS 3.0
7.8 high
EPSS
<1%p10
Published
()
Modified
Description

When handling the vendor command there exists a potential buffer overflow due to lack of input validation of data buffer received in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, MDM9640, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS405, QCS605, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24

Vendors
qualcomm
Products
mdm9607 firmware, mdm9640 firmware, msm8996au firmware, qca6174a firmware, qca6574au firmware, qca9377 firmware, qca9379 firmware, qcs405 firmware, qcs605 firmware, sd 210 firmware, sd 212 firmware, sd 205 firmware
Weakness
CWE-119
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.