CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AI Score
Confidence
High
EPSS
Percentile
25.0%
Possible buffer over read due to lack of length check while flashing meta images in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Vendor | Product | Version | CPE |
---|---|---|---|
qualcomm | apq8009w_firmware | - | cpe:2.3:o:qualcomm:apq8009w_firmware:-:*:*:*:*:*:*:* |
qualcomm | apq8009w | - | cpe:2.3:h:qualcomm:apq8009w:-:*:*:*:*:*:*:* |
qualcomm | aqt1000_firmware | - | cpe:2.3:o:qualcomm:aqt1000_firmware:-:*:*:*:*:*:*:* |
qualcomm | aqt1000 | - | cpe:2.3:h:qualcomm:aqt1000:-:*:*:*:*:*:*:* |
qualcomm | msm8909w_firmware | - | cpe:2.3:o:qualcomm:msm8909w_firmware:-:*:*:*:*:*:*:* |
qualcomm | msm8909w | - | cpe:2.3:h:qualcomm:msm8909w:-:*:*:*:*:*:*:* |
qualcomm | qca4020_firmware | - | cpe:2.3:o:qualcomm:qca4020_firmware:-:*:*:*:*:*:*:* |
qualcomm | qca4020 | - | cpe:2.3:h:qualcomm:qca4020:-:*:*:*:*:*:*:* |
qualcomm | qca6174a_firmware | - | cpe:2.3:o:qualcomm:qca6174a_firmware:-:*:*:*:*:*:*:* |
qualcomm | qca6174a | - | cpe:2.3:h:qualcomm:qca6174a:-:*:*:*:*:*:*:* |
[
{
"product": "Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables",
"vendor": "Qualcomm, Inc.",
"versions": [
{
"status": "affected",
"version": "APQ8009W, AQT1000, MSM8909W, QCA4020, QCA6174A, QCA6420, QCA6430, QCA9379, Qualcomm215, SD 675, SD205, SD210, SD675, SD678, SD720G, SD730, SD855, SDA429W, SDM429W, SDX50M, SDX55, SDX55M, SM6250, WCD9326, WCD9341, WCD9370, WCD9375, WCD9380, WCN3610, WCN3615, WCN3620, WCN3660B, WCN3680, WCN3680B, WCN3950, WCN3980, WCN3988, WCN3991, WCN3998, WSA8810, WSA8815"
}
]
}
]
More
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AI Score
Confidence
High
EPSS
Percentile
25.0%