CVE-2019-2338 Information
Feb 14, 2021
cve
Description
Crafted image that has a valid signature from a non-QC entity can be loaded which can read/write memory that belongs to the secure world in Snapdragon Auto Snapdragon Compute Snapdragon Connectivity Snapdragon Consumer IOT Snapdragon Industrial IOT Snapdragon Mobile Snapdragon Wired Infrastructure and Networking in MDM9205 MSM8998 QCS404 QCS605 SDA660 SDA845 SDM630 SDM636 SDM660 SDM670 SDM710 SDM845 SDM850 SDX24 SM6150 SM7150 SM8150 SXR1130 SXR2130
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Reference
https://www.qualcomm.com/company/product-security/bulletins/november-2019-bulletin
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
7.1
Share on: