First published: Mon Mar 02 2020(Updated: )
The size of a buffer is determined by addition and multiplications operations that have the potential to overflow due to lack of bound check in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, QCS404, Rennell, SC8180X, SDM845, SDM850, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm 9205 Firmware | ||
Qualcomm 9205 | ||
qualcomm QCS404 firmware | ||
qualcomm QCS404 | ||
qualcomm Rennell firmware | ||
qualcomm Rennell | ||
qualcomm SC8180X firmware | ||
qualcomm SC8180X | ||
qualcomm SDM845 firmware | ||
qualcomm SDM845 | ||
qualcomm sdm850 firmware | ||
qualcomm sdm850 | ||
Qualcomm sdx55 firmware | ||
Qualcomm sdx55 | ||
Qualcomm SM6150 | ||
Qualcomm SM6150 Firmware | ||
Qualcomm SM7150 Firmware | ||
qualcomm SM7150 firmware | ||
qualcomm SM8150 firmware | ||
qualcomm SM8150 | ||
qualcomm SM8250 firmware | ||
Qualcomm SM8250 | ||
qualcomm SXR2130 firmware | ||
qualcomm SXR2130 | ||
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14030 has been rated as high severity due to the potential for an overflow in buffer size calculations.
To fix CVE-2019-14030, apply the appropriate firmware updates provided by Qualcomm for the affected devices.
CVE-2019-14030 affects various Qualcomm devices including Snapdragon models and specific firmware versions.
CVE-2019-14030 is primarily considered a local vulnerability, as it can exploit buffer overflows on affected devices.
Exploitation of CVE-2019-14030 would require local access to the affected devices, making remote exploitation unlikely.