First published: Mon Aug 03 2020(Updated: )
u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-provisioned after a user data erase or a factory reset' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Kamorta, Nicobar, QCS404, QCS610, Rennell, SA515M, SA6155P, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
qualcomm Kamorta firmware | ||
qualcomm Kamorta | ||
qualcomm Nicobar firmware | ||
qualcomm Nicobar | ||
qualcomm QCS404 firmware | ||
qualcomm QCS404 | ||
qualcomm qcs610 firmware | ||
qualcomm qcs610 | ||
qualcomm Rennell firmware | ||
qualcomm Rennell | ||
Qualcomm sa515m firmware | ||
Qualcomm sa515m | ||
Qualcomm Sa6155p Firmware | ||
qualcomm SA6155P | ||
Qualcomm SC7180P Firmware | ||
Qualcomm SC7180P Firmware | ||
qualcomm SC8180X firmware | ||
qualcomm SC8180X | ||
Qualcomm sdx55 firmware | ||
Qualcomm sdx55 | ||
Qualcomm SM6150 | ||
Qualcomm SM6150 Firmware | ||
Qualcomm SM7150 Firmware | ||
qualcomm SM7150 firmware | ||
qualcomm SM8150 firmware | ||
qualcomm SM8150 | ||
qualcomm SM8250 firmware | ||
Qualcomm SM8250 | ||
qualcomm SXR2130 firmware | ||
qualcomm SXR2130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-14089.
The severity of CVE-2019-14089 is high with a severity value of 7.8.
CVE-2019-14089 impacts Snapdragon Auto.
Yes, Google Android is affected by CVE-2019-14089.
To fix CVE-2019-14089, you should refer to the official August 2020 security bulletin from Qualcomm and follow the recommended mitigation steps.