CVE-2019-2257

HIGH

Snapdragon Auto et al - Privilege Escalation

Title source: llm
STIX 2.1

Description

Wrong permissions in configuration file can lead to unauthorized permission in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9607, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 855, SDA660, SDM660, SDX20, SDX24

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 6.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (24)
qualcomm/mdm9150_firmware
qualcomm/mdm9607_firmware
qualcomm/mdm9650_firmware
qualcomm/msm8909w_firmware
qualcomm/msm8996au_firmware
qualcomm/qcs405_firmware
qualcomm/qcs605_firmware
qualcomm/sd_205_firmware
qualcomm/sd_210_firmware
qualcomm/sd_212_firmware
... and 14 more
Published Jun 14, 2019
Tracked Since Feb 18, 2026