CVE-2019-10538

EUVD-2019-2342
Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address range which can compromise HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM660, SDX20, SDX24
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
Affected Products (NVD)
VendorProductVersion
qualcommmsm8909w_firmware
-
qualcommmsm8996au_firmware
-
qualcommqcs405_firmware
-
qualcommqcs605_firmware
-
qualcommqualcomm_215_firmware
-
qualcommsd_425_firmware
-
qualcommsd_439_firmware
-
qualcommsd_429_firmware
-
qualcommsd_450_firmware
-
qualcommsd_625_firmware
-
qualcommsd_632_firmware
-
qualcommsd_636_firmware
-
qualcommsd_665_firmware
-
qualcommsd_675_firmware
-
qualcommsd_712_firmware
-
qualcommsd_710_firmware
-
qualcommsd_670_firmware
-
qualcommsd_730_firmware
-
qualcommsd_820a_firmware
-
qualcommsd_845_firmware
-
qualcommsd_850_firmware
-
qualcommsd_855_firmware
-
qualcommsda660_firmware
-
qualcommsdm439_firmware
-
qualcommsdm660_firmware
-
qualcommsdx20_firmware
-
qualcommsdx24_firmware
-
𝑥
= Vulnerable software versions