First published: Mon May 04 2020(Updated: )
Improper permissions in XBL_SEC region enable user to update XBL_SEC code and data and divert the RAM dump path to normal cold boot path in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, MSM8998, QCS404, QCS605, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SM8150, SXR1130, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm Kamorta | ||
qualcomm Kamorta firmware | ||
Qualcomm MSM8998 | ||
Qualcomm 8998 | ||
Qualcomm QCS404 Firmware | ||
Qualcomm QCS404 Firmware | ||
Qualcomm ZZ QCS605 firmware | ||
Qualcomm QCS605 Firmware | ||
Qualcomm SDA660 | ||
Qualcomm SDA660 | ||
Qualcomm SD845 Firmware | ||
Qualcomm Snapdragon 845 | ||
qualcomm SDM630 firmware | ||
qualcomm SDM630 | ||
Qualcomm SD 636 Firmware | ||
Qualcomm SDM636 Firmware | ||
Qualcomm SD660 Firmware | ||
Qualcomm Snapdragon 660 | ||
Qualcomm SD 670 Firmware | ||
Qualcomm SDM670 Firmware | ||
Qualcomm SD710 Firmware | ||
Qualcomm Snapdragon 710 | ||
Qualcomm SDA/SDM845 Firmware | ||
Qualcomm Snapdragon 845 | ||
Qualcomm Snapdragon 850 Firmware | ||
Qualcomm SD850 | ||
Qualcomm SM8150P Firmware | ||
Qualcomm SM8150 Fusion | ||
Qualcomm SXR1130 | ||
Qualcomm SXR1130 Firmware | ||
qualcomm SXR2130P firmware | ||
Qualcomm SXR2130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-14054 is classified as high due to improper permissions that can lead to unauthorized access and manipulation.
To fix CVE-2019-14054, update the affected Qualcomm firmware to the latest version provided by Qualcomm.
CVE-2019-14054 affects several Qualcomm products, including the Kamorta, MSM8998, and various Snapdragon firmware versions.
CVE-2019-14054 can facilitate attacks that allow an attacker to exploit improper permissions to update code and potentially access sensitive RAM dumps.
CVE-2019-14054 is classified as a software vulnerability resulting from firmware design flaws in Qualcomm devices.