CVE-2019-2317

CRITICAL

Snapdragon Auto-SDM632 - Info Disclosure

Title source: llm
STIX 2.1

Description

The secret key used to make the Initial Sequence Number in the TCP SYN packet could be brute forced and therefore can be predicted in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, Nicobar, QCM2150, QM215, SC8180X, SDM429, SDM439, SDM450, SDM632, SDX24, SDX55, SM6150, SM7150, SM8150

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0067
EPSS Percentile 47.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-330
Status published
Products (20)
qualcomm/msm8905_firmware
qualcomm/msm8909_firmware
qualcomm/msm8917_firmware
qualcomm/msm8920_firmware
qualcomm/msm8937_firmware
qualcomm/msm8940_firmware
qualcomm/msm8953_firmware
qualcomm/nicobar_firmware
qualcomm/qcm2150_firmware
qualcomm/qm215_firmware
... and 10 more
Published Mar 05, 2020
Tracked Since Feb 18, 2026