CVE-2019-14007: Medium severity Google Android vulnerability
Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a potential side channel for SUI corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9650, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCS404, QCS405, QCS605, QM215, Rennell, SA6155P, SC7180, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14007?
CVE-2019-14007 has a medium severity rating due to its potential impact on device security.
How can I mitigate CVE-2019-14007?
Mitigation of CVE-2019-14007 involves updating affected Qualcomm firmware and ensuring devices are running the latest security patches.
Which devices are impacted by CVE-2019-14007?
CVE-2019-14007 affects various Qualcomm Snapdragon products including APQ, MDM, MSM, and QCS series across different firmware versions.
What type of vulnerability is identified in CVE-2019-14007?
CVE-2019-14007 is classified as a timing side channel vulnerability due to non-time-constant comparison functions.
Is CVE-2019-14007 a remote exploit vulnerability?
CVE-2019-14007 is not considered a remote exploit vulnerability as it requires local access to the affected devices.