First published: Mon Jul 01 2019(Updated: )
Firmware is getting into loop of overwriting memory when scan command is given from host because of improper validation. in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ8074, QCA8081, QCS404, QCS405, QCS605, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Ipq8074 Firmware | ||
Qualcomm Ipq8074 | ||
Qualcomm Qca8081 Firmware | ||
Google Android | ||
Qualcomm Qcs404 Firmware | ||
Google Android | ||
Qualcomm Qcs405 Firmware | ||
Qualcomm Qcs405 | ||
Qualcomm Qcs605 Firmware | ||
Google Android | ||
Qualcomm Sd 425 Firmware | ||
Qualcomm Sd 425 | ||
Google Android | ||
Google Android | ||
Qualcomm Sd 430 Firmware | ||
Google Android | ||
Google Android | ||
Qualcomm Sd 435 | ||
Qualcomm Sd 450 Firmware | ||
Qualcomm Sd 450 | ||
Qualcomm Sd 625 Firmware | ||
Qualcomm Sd 625 | ||
Qualcomm Sd 636 Firmware | ||
Qualcomm Sd 636 | ||
Qualcomm Sd 712 Firmware | ||
Qualcomm Sd 712 | ||
Qualcomm Sd 710 Firmware | ||
Qualcomm Sd 710 | ||
Qualcomm Sd 670 Firmware | ||
Qualcomm Sd 670 | ||
Google Android | ||
Google Android | ||
Qualcomm Sd 835 Firmware | ||
Qualcomm Sd 835 | ||
Qualcomm Sd 845 Firmware | ||
Qualcomm Sd 845 | ||
Qualcomm Sd 850 Firmware | ||
Qualcomm Sd 850 | ||
Qualcomm Sd 855 Firmware | ||
Qualcomm Sd 855 | ||
Google Android | ||
Qualcomm Sd 8cx | ||
Google Android | ||
Google Android | ||
Qualcomm Sdm630 Firmware | ||
Qualcomm Sdm630 | ||
Qualcomm Sdm660 Firmware | ||
Qualcomm Sdm660 | ||
Google Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2346 is a vulnerability in Qualcomm IPQ8074 firmware that allows for a loop of overwriting memory when a scan command is given from the host due to improper validation.
Google Android and Qualcomm IPQ8074 firmware are affected by CVE-2019-2346.
CVE-2019-2346 has a severity of 7.8 (high).
To fix CVE-2019-2346, it is recommended to apply the latest security updates provided by Google and Qualcomm.
You can find more information about CVE-2019-2346 on the Qualcomm and Android security bulletins.