First published: Tue Sep 03 2019(Updated: )
ADSP can be compromised since it`s a general-purpose CPU processing untrusted data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ8064, IPQ8074, MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm IPQ4019 | ||
Qualcomm IPQ4019 Firmware | ||
Qualcomm IPQ8064 Firmware | ||
Qualcomm IPQ8064 Firmware | ||
Qualcomm IPQ8074 Firmware | ||
Qualcomm IPQ8074A | ||
Qualcomm MDM9150 firmware | ||
Qualcomm MDM9150 firmware | ||
Qualcomm MDM9206 | ||
Qualcomm MDM9206 firmware | ||
Qualcomm MD9607 Firmware | ||
Qualcomm MDM9607 firmware | ||
qualcomm mdm9640 firmware | ||
Qualcomm MDM9640 | ||
Qualcomm MDM9650 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm MSM8909W | ||
Qualcomm Snapdragon 8909 | ||
qualcomm MSM8996AU firmware | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS405 Firmware | ||
Qualcomm ZZ QCS605 firmware | ||
Qualcomm QCS605 Firmware | ||
Qualcomm 215 Mobile Firmware | ||
Qualcomm 215 Firmware | ||
Qualcomm SD210 Firmware | ||
Qualcomm SD 210 Firmware | ||
Qualcomm SD 212 | ||
Qualcomm SD 212 Firmware | ||
Qualcomm SD205 Firmware | ||
Qualcomm SD205 Firmware | ||
Qualcomm SDR425 Firmware | ||
Qualcomm Snapdragon 425 | ||
Qualcomm SD427 Firmware | ||
Qualcomm SD 427 firmware | ||
Qualcomm SD 430 Firmware | ||
Qualcomm SD 430 Firmware | ||
qualcomm sd435 firmware | ||
Qualcomm Snapdragon 435 | ||
Qualcomm SD 439 | ||
Qualcomm SD 439 firmware | ||
Qualcomm SD429 Firmware | ||
Qualcomm SD 429 Firmware | ||
Qualcomm SDM450 Firmware | ||
Qualcomm SDM450 | ||
Qualcomm SD615 Firmware | ||
Qualcomm Snapdragon 615 | ||
Qualcomm Snapdragon 616 firmware | ||
Qualcomm Snapdragon 616 firmware | ||
Qualcomm Snapdragon 415 Firmware | ||
Qualcomm Snapdragon 415 | ||
Qualcomm SD 625 Firmware | ||
Qualcomm Snapdragon 625 | ||
Qualcomm SD632 Firmware | ||
Qualcomm SD 632 firmware | ||
Qualcomm SDM636 Firmware | ||
Qualcomm Snapdragon 636 | ||
Qualcomm Snapdragon 665 | ||
Qualcomm Snapdragon 665 | ||
Qualcomm SD 675 Firmware | ||
Qualcomm Snapdragon 675 | ||
Qualcomm Snapdragon 712 Firmware | ||
Qualcomm Snapdragon 712 | ||
qualcomm sdm710 firmware | ||
Qualcomm Snapdragon 710 | ||
Qualcomm SDM670 Firmware | ||
Qualcomm SDM670 | ||
Qualcomm SD 730 Firmware | ||
Qualcomm Snapdragon 730 | ||
Qualcomm SD820 Firmware | ||
Qualcomm SD820 Firmware | ||
Qualcomm SD820A Firmware | ||
Qualcomm SD820A Firmware | ||
Qualcomm SD835 Firmware | ||
Qualcomm Snapdragon 835 | ||
Qualcomm SDA845 Firmware | ||
Qualcomm SD845 | ||
Qualcomm SD850 Firmware | ||
Qualcomm SD850 | ||
Qualcomm SD855 Firmware | ||
Qualcomm SD855 Firmware | ||
Qualcomm SDA660 | ||
Qualcomm SDA660 | ||
qualcomm SDM439 firmware | ||
Qualcomm SDM439 Firmware | ||
qualcomm SDM630 firmware | ||
qualcomm SDM630 | ||
Qualcomm SD660 Firmware | ||
Qualcomm Snapdragon 660 | ||
Qualcomm SDX20 Firmware | ||
Qualcomm SDX20 Firmware | ||
Qualcomm SDX24 | ||
Qualcomm SDX24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10491 has a severity rating of high due to the potential for exploitation leading to unauthorized access or execution of arbitrary code.
To fix CVE-2019-10491, apply the appropriate security updates provided by Qualcomm or your device manufacturer.
CVE-2019-10491 affects various devices powered by Qualcomm Snapdragon processors, including those used in mobile, automotive, and IoT applications.
Mitigation steps for CVE-2019-10491 include ensuring your device firmware is up to date and avoiding the use of untrusted applications.
Yes, CVE-2019-10491 relates to vulnerabilities in the audio processing components of Qualcomm Snapdragon chips that handle untrusted data.