CVE-2019-10540

CRITICAL

Qualcomm Ipq8074 Firmware - Buffer Overflow

Title source: rule
STIX 2.1

Description

Buffer overflow in WLAN NAN function due to lack of check of count value received in NAN availability attribute in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ8074, MSM8996AU, QCA6174A, QCA6574AU, QCA8081, QCA9377, QCA9379, QCS404, QCS405, QCS605, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SXR1130

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0031
EPSS Percentile 53.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (27)
qualcomm/ipq8074_firmware
qualcomm/msm8996au_firmware
qualcomm/qca6174a_firmware
qualcomm/qca6574au_firmware
qualcomm/qca8081_firmware
qualcomm/qca9377_firmware
qualcomm/qca9379_firmware
qualcomm/qcs404_firmware
qualcomm/qcs405_firmware
qualcomm/qcs605_firmware
... and 17 more
Published Sep 30, 2019
Tracked Since Feb 18, 2026