CVE-2019-14009 PUBLISHED CVSS 7.800000190734863 HIGH

Out of bound memory access while processing TZ command handler due to improper input validation on response length received from user in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8098, MDM9150, MDM9607, MDM9650, MSM8905, MSM8909, MSM8998, SDA660, SDA845, SDM630, SDM636, SDM660, SDM845, SDM850, SXR2130

EPSS 0.03% · 9.5th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.03%
9.5th percentile

Affected Products

VendorProductVersions
qualcommmsm8909_firmware
qualcommsdm660_firmware
Qualcomm, Inc.Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and NetworkingAPQ8009, APQ8098, MDM9150, MDM9607, MDM9650, MSM8905, MSM8909, MSM8998, SDA660, SDA845, SDM630, SDM636, SDM660, SDM845, SDM850, SXR2130
qualcommsda660_firmware
qualcommmdm9150_firmware
qualcommmsm8905_firmware
qualcommsdm850_firmware
qualcommmdm9607_firmware
qualcommsxr2130_firmware
qualcommsdm630_firmware
qualcommsdm845_firmware
qualcommmdm9650_firmware
qualcommsda845_firmware
qualcommmsm8998_firmware
qualcommapq8098_firmware
qualcommapq8009_firmware
qualcommsdm636_firmware

Timeline

References

Open in Interactive Console →