CVE-2019-10625: High severity qualcomm apq8009w firmware vulnerability
Out of bound access in diag services when DCI command buffer reallocation is not done properly with required capacity in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8096AU, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, QCS605, Rennell, SC8180X, SDM429W, SDM710, SDX55, SM7150, SM8150
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10625?
CVE-2019-10625 is categorized as a medium severity vulnerability.
How do I fix CVE-2019-10625?
To mitigate CVE-2019-10625, ensure firmware updates are applied that address the out-of-bounds access in diagnosis services.
Which devices are affected by CVE-2019-10625?
CVE-2019-10625 affects various Qualcomm Snapdragon devices, including APQ8009, APQ8096AU, MDM9206, MDM9207C, MDM9607, and others.
What type of vulnerability is CVE-2019-10625?
CVE-2019-10625 is an out-of-bounds access vulnerability that occurs when DCI command buffer reallocation is not managed properly.
Can CVE-2019-10625 be exploited remotely?
CVE-2019-10625 may allow for remote code execution if an attacker can send crafted DCI commands to the affected devices.