CVE-2019-10483

MEDIUM

Qualcomm APQ8009 and related firmware - Timing Side-Channel in QTEE via Non-Constant-Time Comparison

Title source: llm
STIX 2.1

Description

Side channel issue in QTEE due to usage of non-time-constant comparison function such as memcmp or strcmp in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8016, APQ8017, APQ8053, APQ8076, APQ8096, APQ8096AU, APQ8098, IPQ8074, MDM9150, MDM9205, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, QCA8081, QCS404, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX55, SM6150, SM7150, SM8150, SXR1130, SXR2130

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0004
EPSS Percentile 13.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-203
Status published
Products (50)
qualcomm/apq8009_firmware
qualcomm/apq8016_firmware
qualcomm/apq8017_firmware
qualcomm/apq8053_firmware
qualcomm/apq8076_firmware
qualcomm/apq8096_firmware
qualcomm/apq8096au_firmware
qualcomm/apq8098_firmware
qualcomm/ipq8074_firmware
qualcomm/mdm9150_firmware
... and 40 more
Published Apr 16, 2020
Tracked Since Feb 18, 2026