CVE-2019-10622 PUBLISHED CVSS 9.100000381469727 CRITICAL

Out of bound memory access can happen while parsing ADSP message due to lack of check of size of payload received from userspace in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8096AU, IPQ4019, IPQ6018, IPQ8064, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, QCN7605, QCS605, SC8180X, SDM710, SDX24, SDX55, SM8150, SM8250, SXR2130

EPSS 0.18% · 38.9th percentile

Risk Scores

CVSS v3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS Score
0.18%
38.9th percentile

Affected Products

VendorProductVersions
qualcommipq4019_firmware
qualcommsdx55_firmware
qualcommqcs605_firmware
qualcommmdm9607_firmware
qualcommapq8009_firmware
qualcommsdm710_firmware
qualcommsm8250_firmware
qualcommipq8074_firmware
qualcommsxr2130_firmware
qualcommqcn7605_firmware
qualcommmdm9640_firmware
qualcommmdm9650_firmware
qualcommmdm9206_firmware
qualcommsm8150_firmware
qualcommmdm9207c_firmware
qualcommipq6018_firmware
Qualcomm, Inc.Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and NetworkingAPQ8009, APQ8096AU, IPQ4019, IPQ6018, IPQ8064, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, QCN7605, QCS605, SC8180X, SDM710, SDX24, SDX55, SM8150, SM8250, SXR2130
qualcommipq8064_firmware
qualcommsdx24_firmware
qualcommapq8096au_firmware

…and 1 more

Timeline

References

Open in Interactive Console →