CVE-2019-2289: Critical severity android vulnerability
Lack of integrity check allows MODEM to accept any NAS messages which can result into authentication bypass of NAS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8976, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SnapdragonHighMed2016, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2289?
CVE-2019-2289 is classified as a critical vulnerability due to its potential for authentication bypass.
How do I fix CVE-2019-2289?
To fix CVE-2019-2289, it is recommended to apply the latest firmware updates provided by Qualcomm.
Which devices are affected by CVE-2019-2289?
CVE-2019-2289 affects various Qualcomm Snapdragon platforms, including APQ8009, APQ8017, and many more as detailed in the vulnerability report.
What are the impacts of CVE-2019-2289?
The impact of CVE-2019-2289 includes the ability for attackers to bypass authentication mechanisms, potentially leading to unauthorized access.
Is CVE-2019-2289 being actively exploited?
As of now, there have been no reported active exploits of CVE-2019-2289, but it remains a serious concern.