CVE-2019-2337: High severity android vulnerability
While Skipping unknown IES, EMM is reading the buffer even if the no of bytes to read are more than message length which may cause device to shutdown in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8976, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SnapdragonHighMed2016, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2337?
CVE-2019-2337 is classified as a critical vulnerability due to its potential to cause device shutdowns.
How do I fix CVE-2019-2337?
Fixing CVE-2019-2337 involves updating the affected firmware to a version that addresses this vulnerability.
What devices are affected by CVE-2019-2337?
CVE-2019-2337 affects various Snapdragon platforms, including Snapdragon Auto, Compute, Consumer IoT, Industrial IoT, Mobile, and Wearables.
What are the risks associated with CVE-2019-2337?
The risks associated with CVE-2019-2337 include potential device shutdowns that could disrupt normal operation and functionality.
Is there a workaround for CVE-2019-2337?
There is no officially documented workaround for CVE-2019-2337; users are advised to apply firmware updates as soon as they are available.