← Volver a CVEs
CVE-2019-10481
HIGH7.8
Descripcion
Out of bound access occurs while handling the WMI FW event due to lack of check of buffer argument which comes directly from the WLAN FW in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8096AU, IPQ4019, IPQ8064, IPQ8074, MDM9607, MSM8996AU, QCA6574AU, QCA8081, QCN7605, SDX55, SM6150, SM7150, SM8150
Detalles CVE
Puntuacion CVSS v3.17.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueLOCAL
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado12/18/2019
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
qualcomm:apq8096auqualcomm:apq8096au_firmwarequalcomm:ipq4019qualcomm:ipq4019_firmwarequalcomm:ipq8064qualcomm:ipq8064_firmwarequalcomm:ipq8074qualcomm:ipq8074_firmwarequalcomm:mdm9607qualcomm:mdm9607_firmwarequalcomm:msm8996auqualcomm:msm8996au_firmwarequalcomm:qca6574auqualcomm:qca6574au_firmwarequalcomm:qca8081qualcomm:qca8081_firmwarequalcomm:qcn7605qualcomm:qcn7605_firmwarequalcomm:sdx55qualcomm:sdx55_firmwarequalcomm:sm6150qualcomm:sm6150_firmwarequalcomm:sm7150qualcomm:sm7150_firmwarequalcomm:sm8150qualcomm:sm8150_firmware
Debilidades (CWE)
CWE-129
Referencias
https://www.qualcomm.com/company/product-security/bulletins/december-2019-bulletin(product-security@qualcomm.com)
https://www.qualcomm.com/company/product-security/bulletins/december-2019-bulletin(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.