CVE-2019-2278

HIGH

Snapdragon Auto/Mobile/IOT - Auth Bypass

Title source: llm
STIX 2.1

Description

User keystore signature is ignored in boot and can lead to bypass boot image signature verification in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile in MDM9607, MDM9640, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 712 / SD 710 / SD 670, SD 845 / SD 850, SDM660

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 4.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-347
Status published
Products (15)
qualcomm/mdm9607_firmware
qualcomm/mdm9640_firmware
qualcomm/sd_425_firmware
qualcomm/sd_427_firmware
qualcomm/sd_430_firmware
qualcomm/sd_435_firmware
qualcomm/sd_450_firmware
qualcomm/sd_625_firmware
qualcomm/sd_636_firmware
qualcomm/sd_670_firmware
... and 5 more
Published Jul 25, 2019
Tracked Since Feb 18, 2026