CVE-2019-14134
Last modified
CVE-2019-14134 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Possible out of bound access in WLAN handler when the received value of length in rx path is shorter than the expected value of country IE in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ8074, QCA8081, QCS605, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130. EPSS estimates a 0.91% chance of exploitation in the next 30 days.
Description
Possible out of bound access in WLAN handler when the received value of length in rx path is shorter than the expected value of country IE in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ8074, QCA8081, QCS605, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Ipq8074 Firmware | All versions |
| Qualcomm | Qca8081 Firmware | All versions |
| Qualcomm | Qcs605 Firmware | All versions |
| Qualcomm | Sda845 Firmware | All versions |
| Qualcomm | Sdm670 Firmware | All versions |
| Qualcomm | Sdm710 Firmware | All versions |
| Qualcomm | Sdm845 Firmware | All versions |
| Qualcomm | Sdm850 Firmware | All versions |
| Qualcomm | Sm6150 Firmware | All versions |
| Qualcomm | Sm7150 Firmware | All versions |
| Qualcomm | Sm8150 Firmware | All versions |
| Qualcomm | Sxr1130 Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-14134?
How severe is CVE-2019-14134?
How do I fix CVE-2019-14134?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-14128Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-1413A security feature bypass vulnerability exists when Microsof…4.3
- CVE-2019-14130Memory corruption can occurs in trusted application if offse…7.8
- CVE-2019-14131Out of bound write can occur in radio measurement request if…9.8
- CVE-2019-14132Buffer over-write when this 0-byte buffer is typecasted to s…9.8
- CVE-2019-14133Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-14135Possible integer overflow to buffer overflow in WLAN while p…7.8
- CVE-2019-14136Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-14137Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-14138Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-14139Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-1414An elevation of privilege vulnerability exists in Visual Stu…7.8
Are you affected by CVE-2019-14134?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
