Lucene search

K
cveQualcommCVE-2019-10531
HistoryNov 06, 2019 - 5:15 p.m.

CVE-2019-10531

2019-11-0617:15:12
CWE-120
qualcomm
web.nvd.nist.gov
36
cve-2019-10531
buffer overflow
system image
snapdragon auto
snapdragon mobile
snapdragon wearables
mdm9607
msm8909w
qualcomm 215
sd 210
sd 212
sd 205
sd 425
sd 439
sd 429
sd 450
sd 625
sd 632
sdm439
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.002

Percentile

59.4%

Incorrect reading of system image resulting in buffer overflow when size of system image is increased in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SDM439

Affected configurations

Nvd
Node
qualcommmdm9607Match-
AND
qualcommmdm9607_firmwareMatch-
Node
qualcommmsm8909wMatch-
AND
qualcommmsm8909w_firmwareMatch-
Node
qualcommqualcomm_215Match-
AND
qualcommqualcomm_215_firmwareMatch-
Node
qualcommsd_210Match-
AND
qualcommsd_210_firmwareMatch-
Node
qualcommsd_212Match-
AND
qualcommsd_212_firmwareMatch-
Node
qualcommsd_205Match-
AND
qualcommsd_205_firmwareMatch-
Node
qualcommsd_425Match-
AND
qualcommsd_425_firmwareMatch-
Node
qualcommsd_439Match-
AND
qualcommsd_439_firmwareMatch-
Node
qualcommsd_429_firmwareMatch-
AND
qualcommsd_429Match-
Node
qualcommsd_450_firmwareMatch-
AND
qualcommsd_450Match-
Node
qualcommsd_625_firmwareMatch-
AND
qualcommsd_625Match-
Node
qualcommsd_632_firmwareMatch-
AND
qualcommsd_632Match-
Node
qualcommsdm439_firmwareMatch-
AND
qualcommsdm439Match-
VendorProductVersionCPE
qualcommmdm9607-cpe:2.3:h:qualcomm:mdm9607:-:*:*:*:*:*:*:*
qualcommmdm9607_firmware-cpe:2.3:o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:*
qualcommmsm8909w-cpe:2.3:h:qualcomm:msm8909w:-:*:*:*:*:*:*:*
qualcommmsm8909w_firmware-cpe:2.3:o:qualcomm:msm8909w_firmware:-:*:*:*:*:*:*:*
qualcommqualcomm_215-cpe:2.3:h:qualcomm:qualcomm_215:-:*:*:*:*:*:*:*
qualcommqualcomm_215_firmware-cpe:2.3:o:qualcomm:qualcomm_215_firmware:-:*:*:*:*:*:*:*
qualcommsd_210-cpe:2.3:h:qualcomm:sd_210:-:*:*:*:*:*:*:*
qualcommsd_210_firmware-cpe:2.3:o:qualcomm:sd_210_firmware:-:*:*:*:*:*:*:*
qualcommsd_212-cpe:2.3:h:qualcomm:sd_212:-:*:*:*:*:*:*:*
qualcommsd_212_firmware-cpe:2.3:o:qualcomm:sd_212_firmware:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 261

CNA Affected

[
  {
    "product": "Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables",
    "vendor": "Qualcomm, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "MDM9607, MSM8909W, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SDM439"
      }
    ]
  }
]

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.002

Percentile

59.4%

Related for CVE-2019-10531