CVE-2019-10575
Last modified
CVE-2019-10575 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in SDA845, SDM845, SDM850. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in SDA845, SDM845, SDM850
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Sda845 Firmware | All versions |
| Qualcomm | Sdm845 Firmware | All versions |
| Qualcomm | Sdm850 Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-10575?
How severe is CVE-2019-10575?
How do I fix CVE-2019-10575?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-10569Stack buffer overflow due to instance id is misplaced inside…7.8
- CVE-2019-1057A remote code execution vulnerability exists when the Micros…7.5
- CVE-2019-10571Snapshot of IB can lead to invalid address access due to mis…7.8
- CVE-2019-10572Improper check in video driver while processing data from vi…9.8
- CVE-2019-10573Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-10574Lack of boundary checks for data offsets received from HLOS …7.1
- CVE-2019-10577Improper input validation while processing SIP URI received …9.1
- CVE-2019-10578Null pointer dereference can occur while parsing the clip wh…7.5
- CVE-2019-10579Buffer over-read can occur while playing the video clip whic…9.1
- CVE-2019-1058Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-10580When kernel thread unregistered listener, Use after free iss…7.8
- CVE-2019-10581NULL is assigned to local instance of audio device pointer a…9.8
Are you affected by CVE-2019-10575?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
