CVE-2019-2257: High severity Google Android vulnerability
Wrong permissions in configuration file can lead to unauthorized permission in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9607, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 855, SDA660, SDM660, SDX20, SDX24
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-2257?
CVE-2019-2257 is a vulnerability related to wrong permissions in configuration file that can lead to unauthorized permission in certain Qualcomm products running Android.
Which Qualcomm products are affected by CVE-2019-2257?
CVE-2019-2257 affects Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9607, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, SD 210, SD 212, SD 205, SD 415, SD 615, SD 616, SD 636, SD 712, SD 710, SD 670, SD 820, SD 820a, SD 855, SDA660, SDM660, SDX20, SDX24 with certain firmware versions.
What is the severity of CVE-2019-2257?
CVE-2019-2257 has a severity rating of high.
How can CVE-2019-2257 be fixed?
To fix CVE-2019-2257, it is recommended to follow the instructions provided in the official Android security bulletin and to update the affected Qualcomm products with the latest firmware patches.
What is CWE-732?
CWE-732 is a classification for the vulnerability related to incorrect permissions.