CVE-2019-10538
EUVD-2019-234230.09.2019, 16:15
Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address range which can compromise HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM660, SDX20, SDX24Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| qualcomm | msm8909w_firmware | - |
| qualcomm | msm8996au_firmware | - |
| qualcomm | qcs405_firmware | - |
| qualcomm | qcs605_firmware | - |
| qualcomm | qualcomm_215_firmware | - |
| qualcomm | sd_425_firmware | - |
| qualcomm | sd_439_firmware | - |
| qualcomm | sd_429_firmware | - |
| qualcomm | sd_450_firmware | - |
| qualcomm | sd_625_firmware | - |
| qualcomm | sd_632_firmware | - |
| qualcomm | sd_636_firmware | - |
| qualcomm | sd_665_firmware | - |
| qualcomm | sd_675_firmware | - |
| qualcomm | sd_712_firmware | - |
| qualcomm | sd_710_firmware | - |
| qualcomm | sd_670_firmware | - |
| qualcomm | sd_730_firmware | - |
| qualcomm | sd_820a_firmware | - |
| qualcomm | sd_845_firmware | - |
| qualcomm | sd_850_firmware | - |
| qualcomm | sd_855_firmware | - |
| qualcomm | sda660_firmware | - |
| qualcomm | sdm439_firmware | - |
| qualcomm | sdm660_firmware | - |
| qualcomm | sdx20_firmware | - |
| qualcomm | sdx24_firmware | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration