10

CVE-2019-10546

Buffer overflow can occur in WLAN firmware while parsing beacon/probe_response frames during roaming in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in APQ8096, APQ8096AU, IPQ6018, IPQ8074, MDM9607, MDM9640, MDM9650, MSM8996AU, Nicobar, QCA6174A, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA8081, QCA9377, QCA9379, QCS404, QCS605, Rennell, SA6155P, SC8180X, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

Data is provided by the National Vulnerability Database (NVD)
QualcommApq8096 Firmware Version-
   QualcommApq8096 Version-
QualcommApq8096au Firmware Version-
   QualcommApq8096au Version-
QualcommIpq6018 Firmware Version-
   QualcommIpq6018 Version-
QualcommIpq8074 Firmware Version-
   QualcommIpq8074 Version-
QualcommMdm9607 Firmware Version-
   QualcommMdm9607 Version-
QualcommMdm9640 Firmware Version-
   QualcommMdm9640 Version-
QualcommMdm9650 Firmware Version-
   QualcommMdm9650 Version-
QualcommMsm8996au Firmware Version-
   QualcommMsm8996au Version-
QualcommNicobar Firmware Version-
   QualcommNicobar Version-
QualcommQca6174a Firmware Version-
   QualcommQca6174a Version-
QualcommQca6574 Firmware Version-
   QualcommQca6574 Version-
QualcommQca6574au Firmware Version-
   QualcommQca6574au Version-
QualcommQca6584 Firmware Version-
   QualcommQca6584 Version-
QualcommQca6584au Firmware Version-
   QualcommQca6584au Version-
QualcommQca8081 Firmware Version-
   QualcommQca8081 Version-
QualcommQca9377 Firmware Version-
   QualcommQca9377 Version-
QualcommQca9379 Firmware Version-
   QualcommQca9379 Version-
QualcommQcs404 Firmware Version-
   QualcommQcs404 Version-
QualcommQcs605 Firmware Version-
   QualcommQcs605 Version-
QualcommRennell Firmware Version-
   QualcommRennell Version-
QualcommSa6155p Firmware Version-
   QualcommSa6155p Version-
QualcommSc8180x Firmware Version-
   QualcommSc8180x Version-
QualcommSda660 Firmware Version-
   QualcommSda660 Version-
QualcommSda845 Firmware Version-
   QualcommSda845 Version-
QualcommSdm630 Firmware Version-
   QualcommSdm630 Version-
QualcommSdm636 Firmware Version-
   QualcommSdm636 Version-
QualcommSdm660 Firmware Version-
   QualcommSdm660 Version-
QualcommSdm670 Firmware Version-
   QualcommSdm670 Version-
QualcommSdm710 Firmware Version-
   QualcommSdm710 Version-
QualcommSdm845 Firmware Version-
   QualcommSdm845 Version-
QualcommSdm850 Firmware Version-
   QualcommSdm850 Version-
QualcommSm6150 Firmware Version-
   QualcommSm6150 Version-
QualcommSm7150 Firmware Version-
   QualcommSm7150 Version-
QualcommSm8150 Firmware Version-
   QualcommSm8150 Version-
QualcommSm8250 Firmware Version-
   QualcommSm8250 Version-
QualcommSxr1130 Firmware Version-
   QualcommSxr1130 Version-
QualcommSxr2130 Firmware Version-
   QualcommSxr2130 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.43% 0.594
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.