First published: Mon Mar 02 2020(Updated: )
Buffer overflow can occur when processing non standard SDP video Image attribute parameter in a VILTE\VOLTE call in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8076, APQ8096, APQ8096AU, APQ8098, MDM9150, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, Rennell, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm APQ8009W Firmware | ||
Qualcomm APQ8009W | ||
Qualcomm APQ8017 | ||
Qualcomm APQ8017 | ||
qualcomm apq8053-ac firmware | ||
Qualcomm APQ8053 Firmware | ||
qualcomm apq8076 firmware | ||
Qualcomm APQ8076 | ||
Qualcomm APQ8096AU Firmware | ||
qualcomm APQ8096SG | ||
Qualcomm APQ8096AU Firmware | ||
Qualcomm APQ8096AU Firmware | ||
qualcomm APQ8098 | ||
Qualcomm 8098 | ||
Qualcomm MDM9150 firmware | ||
Qualcomm MDM9150 firmware | ||
Qualcomm MDM9206 | ||
Qualcomm MDM9206 firmware | ||
Qualcomm MD9607 Firmware | ||
Qualcomm MDM9607 firmware | ||
qualcomm mdm9640 firmware | ||
Qualcomm MDM9640 | ||
Qualcomm MDM9645 | ||
Qualcomm MDM9645 | ||
Qualcomm MDM9650 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm MDM9655 firmware | ||
Qualcomm MDM9655 firmware | ||
Qualcomm 8905 Firmware | ||
Qualcomm 8905 | ||
Qualcomm MSM8909W | ||
Qualcomm MSM8909W | ||
Qualcomm MSM8909W | ||
Qualcomm Snapdragon 8909 | ||
Qualcomm MSM8917 | ||
Qualcomm MSM8917 Firmware | ||
Qualcomm 8920 Firmware | ||
Qualcomm 8920 | ||
Qualcomm 8937 Firmware | ||
qualcomm MSM8937 firmware | ||
qualcomm MSM8940 firmware | ||
Qualcomm 8940 | ||
Qualcomm 8953 Firmware | ||
Qualcomm MSM8953 Firmware | ||
qualcomm MSM8996AU firmware | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm MSM8998 | ||
Qualcomm 8998 | ||
Qualcomm Nicobar | ||
Qualcomm Nicobar | ||
Qualcomm QCM2150 | ||
Qualcomm QCM2150 Firmware | ||
Qualcomm ZZ QCS605 firmware | ||
Qualcomm QCS605 Firmware | ||
Qualcomm 215 Firmware | ||
Qualcomm 215 | ||
Qualcomm Rennell | ||
qualcomm Rennell firmware | ||
qualcomm SC8180X firmware | ||
Qualcomm SC8180X | ||
Qualcomm SDA660 | ||
Qualcomm SDA660 | ||
Qualcomm SD845 Firmware | ||
Qualcomm Snapdragon 845 | ||
Qualcomm SDM429W | ||
Qualcomm SD429 | ||
Qualcomm SDM429W | ||
qualcomm SDM429W firmware | ||
qualcomm SDM439 firmware | ||
Qualcomm SDM439 Firmware | ||
Qualcomm SD 450 Firmware | ||
Qualcomm Snapdragon 450 | ||
qualcomm SDM630 firmware | ||
qualcomm SDM630 | ||
Qualcomm SDM632 | ||
Qualcomm SDM632 | ||
Qualcomm SD 636 Firmware | ||
Qualcomm SDM636 Firmware | ||
Qualcomm SD660 Firmware | ||
Qualcomm Snapdragon 660 | ||
Qualcomm SD 670 Firmware | ||
Qualcomm SDM670 Firmware | ||
Qualcomm SD710 Firmware | ||
Qualcomm Snapdragon 710 | ||
Qualcomm SDA/SDM845 Firmware | ||
Qualcomm Snapdragon 845 | ||
Qualcomm Snapdragon 850 Firmware | ||
Qualcomm SD850 | ||
Qualcomm SDX20 Firmware | ||
Qualcomm SDX20 Firmware | ||
Qualcomm SDX24 | ||
Qualcomm SDX24 | ||
Qualcomm SDX55M Firmware | ||
Qualcomm SDX55 Firmware | ||
qualcomm SM6150P firmware | ||
Qualcomm SM6150P | ||
qualcomm SM7150 firmware | ||
qualcomm SM7150 firmware | ||
Qualcomm SM8150P Firmware | ||
Qualcomm SM8150 Fusion | ||
Qualcomm SXR1130 | ||
Qualcomm SXR1130 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-10593 is categorized as critical due to the potential for a buffer overflow leading to arbitrary code execution.
To fix CVE-2019-10593, you should update the affected Qualcomm firmware or software to the latest version provided by Qualcomm.
CVE-2019-10593 affects various Qualcomm products, including several Snapdragon models utilized in automotive, IoT, and mobile devices.
Yes, CVE-2019-10593 can potentially be exploited remotely during VILTE/VOLTE calls if the target device is running an affected version.
If CVE-2019-10593 is not resolved, it may lead to unauthorized code execution, resulting in device compromise and data breaches.