CVE-2019-10589 PUBLISHED CVSS 9.800000190734863 CRITICAL

Lack of length check of response buffer can lead to buffer over-flow while GP command response buffer handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8017, APQ8053, APQ8098, MDM9206, MDM9607, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, QM215, SDA660, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660

EPSS 0.33% · 55.7th percentile

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.33%
55.7th percentile

Affected Products

VendorProductVersions
qualcommsdm630_firmware
qualcommmsm8940_firmware
qualcommmsm8917_firmware
qualcommmsm8953_firmware
qualcommsda660_firmware
qualcommmdm9206_firmware
qualcommsdm429_firmware
qualcommsdm636_firmware
qualcommsdm660_firmware
qualcommmsm8920_firmware
qualcommsdm439_firmware
qualcommqm215_firmware
qualcommapq8053_firmware
qualcommmsm8937_firmware
qualcommapq8098_firmware
Qualcomm, Inc.Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and NetworkingAPQ8017, APQ8053, APQ8098, MDM9206, MDM9607, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, QM215, SDA660, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660
qualcommsdm450_firmware
qualcommmsm8998_firmware
qualcommapq8017_firmware
qualcommmdm9607_firmware

…and 1 more

Timeline

References

Open in Interactive Console →