CVE-2019-10575

HIGH

Qualcomm SDA845 SDM845 SDM850 Firmware - Improper Verification of Cryptographic Signature

Title source: llm
STIX 2.1

Description

Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in SDA845, SDM845, SDM850

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 3.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-347
Status published
Products (3)
qualcomm/sda845_firmware
qualcomm/sdm845_firmware
qualcomm/sdm850_firmware
Published Apr 16, 2020
Tracked Since Feb 18, 2026