CVE-2019-10624 PUBLISHED CVSS 7.800000190734863 HIGH

While handling the vendor command there is an integer truncation issue that could yield a buffer overflow due to int data type copied to u8 data type in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8096AU, MSM8996AU, QCA6574AU, QCN7605, Rennell, SC8180X, SDM710, SDX55, SM7150, SM8150, SM8250, SXR2130

EPSS 0.05% · 16.9th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.05%
16.9th percentile

Affected Products

VendorProductVersions
qualcommmsm8996au_firmware
qualcommqcn7605_firmware
qualcommsm8150_firmware
Qualcomm, Inc.Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon MobileAPQ8096AU, MSM8996AU, QCA6574AU, QCN7605, Rennell, SC8180X, SDM710, SDX55, SM7150, SM8150, SM8250, SXR2130
qualcommrennell_firmware
qualcommsm8250_firmware
qualcommsc8180x_firmware
qualcommsdx55_firmware
qualcommqca6574au_firmware
qualcommsdm710_firmware
qualcommsm7150_firmware
qualcommsxr2130_firmware
qualcommapq8096au_firmware

Timeline

References

Open in Interactive Console →