CRITICAL · 9.8

CVE-2019-14134

Possible out of bound access in WLAN handler when the received value of length in rx path is shorter than the expected value of country IE in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon In...

Vulnerability Description

Possible out of bound access in WLAN handler when the received value of length in rx path is shorter than the expected value of country IE in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ8074, QCA8081, QCS605, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
QualcommIpq8074 Firmware-
QualcommIpq8074-
QualcommQca8081 Firmware-
QualcommQca8081-
QualcommQcs605 Firmware-
QualcommQcs605-
QualcommSda845 Firmware-
QualcommSda845-
QualcommSdm670 Firmware-
QualcommSdm670-
QualcommSdm710 Firmware-
QualcommSdm710-
QualcommSdm845 Firmware-
QualcommSdm845-
QualcommSdm850 Firmware-
QualcommSdm850-
QualcommSm6150 Firmware-
QualcommSm6150-
QualcommSm7150 Firmware-
QualcommSm7150-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-14134?

CVE-2019-14134 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Possible out of bound access in WLAN handler when the received value of length in rx path is shorter than the expected value of country IE in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon In...

How severe is CVE-2019-14134?

CVE-2019-14134 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2019-14134?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Ipq8074 Firmware, Qualcomm Ipq8074, Qualcomm Qca8081 Firmware, Qualcomm Qca8081, Qualcomm Qcs605 Firmware.