CVE-2019-10538
Last modified
CVE-2019-10538 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address range which can compromise HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM660, SDX20, SDX24. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address range which can compromise HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM660, SDX20, SDX24
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Msm8909w Firmware | All versions |
| Qualcomm | Msm8996au Firmware | All versions |
| Qualcomm | Qcs405 Firmware | All versions |
| Qualcomm | Qcs605 Firmware | All versions |
| Qualcomm | Qualcomm 215 Firmware | All versions |
| Qualcomm | Sd 425 Firmware | All versions |
| Qualcomm | Sd 439 Firmware | All versions |
| Qualcomm | Sd 429 Firmware | All versions |
| Qualcomm | Sd 450 Firmware | All versions |
| Qualcomm | Sd 625 Firmware | All versions |
| Qualcomm | Sd 632 Firmware | All versions |
| Qualcomm | Sd 636 Firmware | All versions |
| Qualcomm | Sd 665 Firmware | All versions |
| Qualcomm | Sd 675 Firmware | All versions |
| Qualcomm | Sd 712 Firmware | All versions |
| Qualcomm | Sd 710 Firmware | All versions |
| Qualcomm | Sd 670 Firmware | All versions |
| Qualcomm | Sd 730 Firmware | All versions |
| Qualcomm | Sd 820a Firmware | All versions |
| Qualcomm | Sd 845 Firmware | All versions |
| Qualcomm | Sd 850 Firmware | All versions |
| Qualcomm | Sd 855 Firmware | All versions |
| Qualcomm | Sda660 Firmware | All versions |
| Qualcomm | Sdm439 Firmware | All versions |
| Qualcomm | Sdm660 Firmware | All versions |
| Qualcomm | Sdx20 Firmware | All versions |
| Qualcomm | Sdx24 Firmware | All versions |
References
- https://www.codeaurora.org/security-bulletin/2019/08/05/august-2019-code-aurora-security-bulletinPatch, Third Party Advisory
- https://www.codeaurora.org/security-bulletin/2019/08/05/august-2019-code-aurora-security-bulletinPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-10538?
How severe is CVE-2019-10538?
How do I fix CVE-2019-10538?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-10532Null-pointer dereference issue can occur while calculating s…9.8
- CVE-2019-10533Out of bound access due to improper validation of array inde…9.8
- CVE-2019-10534Null-pointer dereference can occur while accessing the super…9.8
- CVE-2019-10535Improper validation for loop variable received from firmware…5.5
- CVE-2019-10536Potential double free scenario if driver receives another DI…7.8
- CVE-2019-10537Improper validation of event buffer extracted from FW respon…7.8
- CVE-2019-10539Possible buffer overflow issue due to lack of length check w…9.8
- CVE-2019-1054A security feature bypass vulnerability exists in Edge that …5
- CVE-2019-10540Buffer overflow in WLAN NAN function due to lack of check of…9.8
- CVE-2019-10541Dereference on uninitialized buffer can happen when parsing …9.8
- CVE-2019-10542Buffer over-read may occur when downloading a corrupted firm…9.8
- CVE-2019-10544Improper length check on source buffer to handle userspace d…7.8
Are you affected by CVE-2019-10538?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
