First published: Mon Apr 06 2020(Updated: )
Information disclosure issue occurs as there is no binding between the secure keypad session and the secure display session that allows user to take control of the REE to stop the secure keypad session and read the keypad input. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, MSM8905, MSM8909
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm APQ8009W Firmware | ||
Qualcomm APQ8009W | ||
Qualcomm 8905 Firmware | ||
Qualcomm 8905 | ||
Qualcomm MSM8909W | ||
Qualcomm MSM8909W |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-10608 is high due to the potential for information disclosure.
To fix CVE-2019-10608, update your device firmware to the latest version provided by Qualcomm or the device manufacturer.
CVE-2019-10608 affects devices using Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, and certain firmware versions.
CVE-2019-10608 is an information disclosure vulnerability that allows unauthorized access to keypad input.
CVE-2019-10608 typically requires local access to exploit, thus reducing the risk of remote exploitation.