CVE-2019-14054: High severity android vulnerability
Improper permissions in XBLSEC region enable user to update XBLSEC code and data and divert the RAM dump path to normal cold boot path in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, MSM8998, QCS404, QCS605, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SM8150, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14054?
The severity of CVE-2019-14054 is classified as high due to improper permissions that can lead to unauthorized access and manipulation.
How do I fix CVE-2019-14054?
To fix CVE-2019-14054, update the affected Qualcomm firmware to the latest version provided by Qualcomm.
Which products are affected by CVE-2019-14054?
CVE-2019-14054 affects several Qualcomm products, including the Kamorta, MSM8998, and various Snapdragon firmware versions.
What kind of attacks can CVE-2019-14054 facilitate?
CVE-2019-14054 can facilitate attacks that allow an attacker to exploit improper permissions to update code and potentially access sensitive RAM dumps.
Is CVE-2019-14054 a hardware or software vulnerability?
CVE-2019-14054 is classified as a software vulnerability resulting from firmware design flaws in Qualcomm devices.