CVE-2019-10549

HIGH

Qualcomm MSM/SDM/SM/SDX/SC/QCM/QM Firmware - Null Pointer Dereference via CSEQ Header Response

Title source: llm
STIX 2.1

Description

Null pointer dereference issue can happen due to improper validation of CSEQ header response received from network in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, Nicobar, QCM2150, QM215, Rennell, SC8180X, SDM429, SDM429W, SDM439, SDM450, SDM632, SDX24, SDX55, SM6150, SM7150, SM8150

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0025
EPSS Percentile 47.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (22)
qualcomm/msm8905_firmware
qualcomm/msm8909_firmware
qualcomm/msm8917_firmware
qualcomm/msm8920_firmware
qualcomm/msm8937_firmware
qualcomm/msm8940_firmware
qualcomm/msm8953_firmware
qualcomm/nicobar_firmware
qualcomm/qcm2150_firmware
qualcomm/qm215_firmware
... and 12 more
Published Mar 05, 2020
Tracked Since Feb 18, 2026