CVE-2019-10483 PUBLISHED CVSS 5.5 MEDIUM

Side channel issue in QTEE due to usage of non-time-constant comparison function such as memcmp or strcmp in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8016, APQ8017, APQ8053, APQ8076, APQ8096, APQ8096AU, APQ8098, IPQ8074, MDM9150, MDM9205, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, QCA8081, QCS404, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX55, SM6150, SM7150, SM8150, SXR1130, SXR2130

EPSS 0.04% · 13.6th percentile

Risk Scores

CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.04%
13.6th percentile

Affected Products

VendorProductVersions
qualcommsdm850_firmware
qualcommmsm8940_firmware
qualcommsdm630_firmware
qualcommsdm710_firmware
qualcommmsm8996au_firmware
qualcommsm8150_firmware
qualcommmdm9655_firmware
qualcommqcs605_firmware
qualcommsdx55_firmware
qualcommmsm8909w_firmware
qualcommqca8081_firmware
qualcommmsm8920_firmware
qualcommsdm636_firmware
qualcommsdm660_firmware
qualcommmsm8917_firmware
qualcommmdm9207c_firmware
qualcommsdm845_firmware
qualcommmsm8998_firmware
qualcommmsm8905_firmware
qualcommmdm9650_firmware

…and 33 more

Timeline

References

Open in Interactive Console →