Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-10537


Improper validation of event buffer extracted from FW response can lead to integer overflow, which will allow to pass the length check and eventually will lead to buffer overwrite when event data is copied to context buffer in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, Nicobar, QCA6574AU, QCN7605, QCS405, QCS605, SDM660, SDM845, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130


Published

2019-12-18T06:15:11.940

Last Modified

2024-11-21T04:19:23.337

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-190

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qualcomm mdm9607_firmware - Yes
Hardware qualcomm mdm9607 - No
Operating System qualcomm nicobar_firmware - Yes
Hardware qualcomm nicobar - No
Operating System qualcomm qca6574au_firmware - Yes
Hardware qualcomm qca6574au - No
Operating System qualcomm qcn7605_firmware - Yes
Hardware qualcomm qcn7605 - No
Operating System qualcomm qcs405_firmware - Yes
Hardware qualcomm qcs405 - No
Operating System qualcomm qcs605_firmware - Yes
Hardware qualcomm qcs605 - No
Operating System qualcomm sdm660_firmware - Yes
Hardware qualcomm sdm660 - No
Operating System qualcomm sdm845_firmware - Yes
Hardware qualcomm sdm845 - No
Operating System qualcomm sdx55_firmware - Yes
Hardware qualcomm sdx55 - No
Operating System qualcomm sm6150_firmware - Yes
Hardware qualcomm sm6150 - No
Operating System qualcomm sm7150_firmware - Yes
Hardware qualcomm sm7150 - No
Operating System qualcomm sm8150_firmware - Yes
Hardware qualcomm sm8150 - No
Operating System qualcomm sm8250_firmware - Yes
Hardware qualcomm sm8250 - No
Operating System qualcomm sxr1130_firmware - Yes
Hardware qualcomm sxr1130 - No
Operating System qualcomm sxr2130_firmware - Yes
Hardware qualcomm sxr2130 - No

References