TROYANOSYVIRUS
Retour aux CVEs

CVE-2019-10535

MEDIUM
5.5

Description

Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iterating through loop in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in APQ8053, APQ8096AU, APQ8098, MDM9640, MSM8996AU, MSM8998, QCA6574AU, QCN7605, QCS405, QCS605, SDA845, SDM845, SDX20

Details CVE

Score CVSS v3.15.5
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie11/21/2019
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

qualcomm:apq8053qualcomm:apq8053_firmwarequalcomm:apq8096auqualcomm:apq8096au_firmwarequalcomm:apq8098qualcomm:apq8098_firmwarequalcomm:mdm9640qualcomm:mdm9640_firmwarequalcomm:msm8996auqualcomm:msm8996au_firmwarequalcomm:msm8998qualcomm:msm8998_firmwarequalcomm:qca6574auqualcomm:qca6574au_firmwarequalcomm:qcn7605qualcomm:qcn7605_firmwarequalcomm:qcs405qualcomm:qcs405_firmwarequalcomm:qcs605qualcomm:qcs605_firmwarequalcomm:sda845qualcomm:sda845_firmwarequalcomm:sdm845qualcomm:sdm845_firmwarequalcomm:sdx20qualcomm:sdx20_firmware

Faiblesses (CWE)

CWE-20CWE-119

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.