CVE-2019-10589

CRITICAL

Qualcomm Apq8017 Firmware - Buffer Overflow

Title source: rule
STIX 2.1

Description

Lack of length check of response buffer can lead to buffer over-flow while GP command response buffer handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8017, APQ8053, APQ8098, MDM9206, MDM9607, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, QM215, SDA660, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0033
EPSS Percentile 55.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (20)
qualcomm/apq8017_firmware
qualcomm/apq8053_firmware
qualcomm/apq8098_firmware
qualcomm/mdm9206_firmware
qualcomm/mdm9607_firmware
qualcomm/msm8917_firmware
qualcomm/msm8920_firmware
qualcomm/msm8937_firmware
qualcomm/msm8940_firmware
qualcomm/msm8953_firmware
... and 10 more
Published Apr 16, 2020
Tracked Since Feb 18, 2026