Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-10623


Possible integer overflow can happen in host driver while processing user controlled string due to improper validation on data received. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCN7605, QCS605, Rennell, SC8180X, SDA845, SDM710, SDX24, SDX55, SM7150, SM8150, SM8250, SXR2130


Published

2020-04-16T11:15:14.057

Last Modified

2024-11-21T04:19:36.610

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.1 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-190

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qualcomm qcn7605_firmware - Yes
Hardware qualcomm qcn7605 - No
Operating System qualcomm qcs605_firmware - Yes
Hardware qualcomm qcs605 - No
Operating System qualcomm rennell_firmware - Yes
Hardware qualcomm rennell - No
Operating System qualcomm sc8180x_firmware - Yes
Hardware qualcomm sc8180x - No
Operating System qualcomm sda845_firmware - Yes
Hardware qualcomm sda845 - No
Operating System qualcomm sdm710_firmware - Yes
Hardware qualcomm sdm710 - No
Operating System qualcomm sdx24_firmware - Yes
Hardware qualcomm sdx24 - No
Operating System qualcomm sdx55_firmware - Yes
Hardware qualcomm sdx55 - No
Operating System qualcomm sm7150_firmware - Yes
Hardware qualcomm sm7150 - No
Operating System qualcomm sm8150_firmware - Yes
Hardware qualcomm sm8150 - No
Operating System qualcomm sm8250_firmware - Yes
Hardware qualcomm sm8250 - No
Operating System qualcomm sxr2130_firmware - Yes
Hardware qualcomm sxr2130 - No

References