CVE-2019-10601

Out of bound access can occur while processing firmware event due to lack of validation of WMI message received from firmware in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8096AU, IPQ4019, IPQ8064, IPQ8074, MSM8996AU, Nicobar, QCA6574AU, QCN7605, QCS405, SDM630, SDM636, SDM660, SDM845, SM6150, SM7150, SM8150
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
qualcommCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
VendorProductVersion
qualcommapq8096au_firmware
-
qualcommipq4019_firmware
-
qualcommipq8064_firmware
-
qualcommipq8074_firmware
-
qualcommmsm8996au_firmware
-
qualcommnicobar_firmware
-
qualcommqca6574au_firmware
-
qualcommqcn7605_firmware
-
qualcommqcs405_firmware
-
qualcommsdm630_firmware
-
qualcommsdm636_firmware
-
qualcommsdm660_firmware
-
qualcommsdm845_firmware
-
qualcommsm6150_firmware
-
qualcommsm7150_firmware
-
qualcommsm8150_firmware
-
𝑥
= Vulnerable software versions