CVE-2019-10507: High severity qualcomm mdm9150 firmware vulnerability
Lack of check of extscan change results received from firmware can lead to an out of buffer read in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS605, SD 210/SD 212/SD 205, SD 425, SD 430, SD 600, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM630, SDM660, SDX20, SDX24
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2019-10507.
What is the severity of CVE-2019-10507?
The severity of CVE-2019-10507 is high.
Which software products are affected by CVE-2019-10507?
CVE-2019-10507 affects Qualcomm MDM9150, MDM9206, MDM9607, MDM9640, and Snapdragon mobile platforms.
What is the CWE ID for CVE-2019-10507?
The CWE ID for CVE-2019-10507 is 125.
How can I fix the vulnerability CVE-2019-10507?
You can fix the vulnerability CVE-2019-10507 by applying the recommended security patches provided by Qualcomm.