CVE-2019-10535 PUBLISHED CVSS 5.5 MEDIUM

Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iterating through loop in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in APQ8053, APQ8096AU, APQ8098, MDM9640, MSM8996AU, MSM8998, QCA6574AU, QCN7605, QCS405, QCS605, SDA845, SDM845, SDX20

EPSS 0.04% · 13.4th percentile

Risk Scores

CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.04%
13.4th percentile

Affected Products

VendorProductVersions
qualcommapq8096au_firmware
qualcommmdm9640_firmware
Qualcomm, Inc.Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & MusicAPQ8053, APQ8096AU, APQ8098, MDM9640, MSM8996AU, MSM8998, QCA6574AU, QCN7605, QCS405, QCS605, SDA845, SDM845, SDX20
qualcommsda845_firmware
qualcommsdx20_firmware
qualcommapq8098_firmware
qualcommmsm8998_firmware
qualcommqcn7605_firmware
qualcommqcs405_firmware
qualcommqcs605_firmware
qualcommqca6574au_firmware
qualcommmsm8996au_firmware
qualcommapq8053_firmware
qualcommsdm845_firmware

Timeline

References

Open in Interactive Console →