CVE-2019-10483: Medium severity Google Android vulnerability
Side channel issue in QTEE due to usage of non-time-constant comparison function such as memcmp or strcmp in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8016, APQ8017, APQ8053, APQ8076, APQ8096, APQ8096AU, APQ8098, IPQ8074, MDM9150, MDM9205, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, QCA8081, QCS404, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX55, SM6150, SM7150, SM8150, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10483?
The severity of CVE-2019-10483 is deemed high due to the potential for exploitation through timing attacks.
How do I fix CVE-2019-10483?
To mitigate CVE-2019-10483, update to the patched version of the firmware provided by your device manufacturer.
What devices are affected by CVE-2019-10483?
CVE-2019-10483 affects various Qualcomm Snapdragon platforms including APQ8009, APQ8016, APQ8017, and several others.
What type of vulnerability is CVE-2019-10483?
CVE-2019-10483 is classified as a side channel vulnerability resulting from non-time-constant comparison functions.
Can CVE-2019-10483 be exploited remotely?
Yes, CVE-2019-10483 can potentially be exploited remotely depending on the implementation and security measures in place.