First published: Mon Mar 02 2020(Updated: )
The size of a buffer is determined by addition and multiplications operations that have the potential to overflow due to lack of bound check in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, QCS404, Rennell, SC8180X, SDM845, SDM850, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm 9205 Firmware | ||
Qualcomm 9205 | ||
Qualcomm QCS404 Firmware | ||
Qualcomm QCS404 Firmware | ||
Qualcomm Rennell Firmware | ||
Qualcomm Rennell Firmware | ||
qualcomm SC8180X firmware | ||
Qualcomm SC8180X | ||
Qualcomm SDA/SDM845 Firmware | ||
Qualcomm Snapdragon 845 | ||
Qualcomm Snapdragon 850 Firmware | ||
Qualcomm SD850 | ||
Qualcomm SDX55M Firmware | ||
Qualcomm SDX55 Firmware | ||
Qualcomm SM6150P firmware | ||
Qualcomm SM6150P | ||
qualcomm SM7150P firmware | ||
qualcomm SM7150 firmware | ||
Qualcomm SM8150P Firmware | ||
Qualcomm SM8150 Fusion | ||
Qualcomm SM8250 | ||
qualcomm SM8250 firmware | ||
Qualcomm SXR2130P Firmware | ||
Qualcomm SXR2130 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14030 has been rated as high severity due to the potential for an overflow in buffer size calculations.
To fix CVE-2019-14030, apply the appropriate firmware updates provided by Qualcomm for the affected devices.
CVE-2019-14030 affects various Qualcomm devices including Snapdragon models and specific firmware versions.
CVE-2019-14030 is primarily considered a local vulnerability, as it can exploit buffer overflows on affected devices.
Exploitation of CVE-2019-14030 would require local access to the affected devices, making remote exploitation unlikely.