10

CVE-2019-10538

Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address range which can compromise HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM660, SDX20, SDX24

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QualcommMsm8909w Firmware Version-
   QualcommMsm8909w Version-
QualcommMsm8996au Firmware Version-
   QualcommMsm8996au Version-
QualcommQcs405 Firmware Version-
   QualcommQcs405 Version-
QualcommQcs605 Firmware Version-
   QualcommQcs605 Version-
QualcommQualcomm 215 Firmware Version-
   QualcommQualcomm 215 Version-
QualcommSd 425 Firmware Version-
   QualcommSd 425 Version-
QualcommSd 439 Firmware Version-
   QualcommSd 439 Version-
QualcommSd 429 Firmware Version-
   QualcommSd 429 Version-
QualcommSd 450 Firmware Version-
   QualcommSd 450 Version-
QualcommSd 625 Firmware Version-
   QualcommSd 625 Version-
QualcommSd 632 Firmware Version-
   QualcommSd 632 Version-
QualcommSd 636 Firmware Version-
   QualcommSd 636 Version-
QualcommSd 665 Firmware Version-
   QualcommSd 665 Version-
QualcommSd 675 Firmware Version-
   QualcommSd 675 Version-
QualcommSd 712 Firmware Version-
   QualcommSd 712 Version-
QualcommSd 710 Firmware Version-
   QualcommSd 710 Version-
QualcommSd 670 Firmware Version-
   QualcommSd 670 Version-
QualcommSd 730 Firmware Version-
   QualcommSd 730 Version-
QualcommSd 820a Firmware Version-
   QualcommSd 820a Version-
QualcommSd 845 Firmware Version-
   QualcommSd 845 Version-
QualcommSd 850 Firmware Version-
   QualcommSd 850 Version-
QualcommSd 855 Firmware Version-
   QualcommSd 855 Version-
QualcommSda660 Firmware Version-
   QualcommSda660 Version-
QualcommSdm439 Firmware Version-
   QualcommSdm439 Version-
QualcommSdm660 Firmware Version-
   QualcommSdm660 Version-
QualcommSdx20 Firmware Version-
   QualcommSdx20 Version-
QualcommSdx24 Firmware Version-
   QualcommSdx24 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.554
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.