CVE-2019-10606 PUBLISHED CVSS 7.800000190734863 HIGH

Out-of-bound access will occur in USB driver due to lack of check to validate the frame size passed by user in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, QCS605, SDX24

EPSS 0.03% · 9.5th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.03%
9.5th percentile

Affected Products

VendorProductVersions
qualcommmdm9607_firmware
qualcommmsm8937_firmware
qualcommmsm8920_firmware
qualcommsdx24_firmware
qualcommmsm8917_firmware
Qualcomm, Inc.Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon WearablesMDM9607, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, QCS605, SDX24
qualcommqcs605_firmware
qualcommmsm8909w_firmware
qualcommmsm8940_firmware

Timeline

References

Open in Interactive Console →