CVE-2019-2289

EUVD-2019-11931
Lack of integrity check allows MODEM to accept any NAS messages which can result into authentication bypass of NAS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8976, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, Snapdragon_High_Med_2016, SXR1130, SXR2130
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
Affected Products (NVD)
VendorProductVersion
qualcommapq8009_firmware
-
qualcommapq8017_firmware
-
qualcommapq8053_firmware
-
qualcommapq8096au_firmware
-
qualcommapq8098_firmware
-
qualcommmdm915_firmware
-
qualcommmdm9205_firmware
-
qualcommmdm9206_firmware
-
qualcommmdm9607_firmware
-
qualcommmdm9615_firmware
-
qualcommmdm9625_firmware
-
qualcommmdm9635m_firmware
-
qualcommmdm9640_firmware
-
qualcommmdm9650_firmware
-
qualcommmdm9655_firmware
-
qualcommmsm8905_firmware
-
qualcommmsm8909_firmware
-
qualcommmsm8909w_firmware
-
qualcommmsm8917_firmware
-
qualcommmsm8920_firmware
-
qualcommmsm8937_firmware
-
qualcommmsm8940_firmware
-
qualcommmsm8953_firmware
-
qualcommmsm8976_firmware
-
qualcommmsm8996au_firmware
-
qualcommmsm8998_firmware
-
qualcommqcm2150_firmware
-
qualcommqcs605_firmware
-
qualcommqm215_firmware
-
qualcommsc8180x_firmware
-
qualcommsda660_firmware
-
qualcommsda845_firmware
-
qualcommsdm429_firmware
-
qualcommsdm439_firmware
-
qualcommsdm450_firmware
-
qualcommsdm630_firmware
-
qualcommsdm632_firmware
-
qualcommsdm636_firmware
-
qualcommsdm660_firmware
-
qualcommsdm670_firmware
-
qualcommsdm710_firmware
-
qualcommsdm845_firmware
-
qualcommsdm850_firmware
-
qualcommsdx20_firmware
-
qualcommsdx55_firmware
-
qualcommsm6150_firmware
-
qualcommsm7150_firmware
-
qualcommsm8150_firmware
-
qualcommsm8250_firmware
-
qualcommsnapdragon_high_med_2016_firmware
-
qualcommsxr1130_firmware
-
qualcommsxr2130_firmware
-
qualcommnicobar_firmware
-
qualcommmsm8939_firmware
-
qualcommsdx24_firmware
-
𝑥
= Vulnerable software versions