CVE-2019-2301

HIGH

Qualcomm Snapdragon - Info Disclosure

Title source: llm
STIX 2.1

Description

Possibility of out-of-bound read if id received from SPI is not in range of FIFO in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ8064, MSM8909W, MSM8996AU, QCA9980, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 712 / SD 710 / SD 670, SD 820A, SD 845 / SD 850, SD 855, SDM439, SDM660, SDX24

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0004
EPSS Percentile 12.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-125
Status published
Products (24)
qualcomm/ipq4019_firmware
qualcomm/ipq8064_firmware
qualcomm/msm8909w_firmware
qualcomm/msm8996au_firmware
qualcomm/qca9980_firmware
qualcomm/qcs605_firmware
qualcomm/qualcomm_215_firmware
qualcomm/sd_425_firmware
qualcomm/sd_429_firmware
qualcomm/sd_439_firmware
... and 14 more
Published Jul 25, 2019
Tracked Since Feb 18, 2026