HIGH · 7.8

CVE-2019-2281

An unauthenticated bitmap image can be loaded in to memory and subsequently cause execution of unverified code. in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Indu...

Vulnerability Description

An unauthenticated bitmap image can be loaded in to memory and subsequently cause execution of unverified code. in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in QCS405, QCS605, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SDX24, SXR1130

CVSS Score

7.8

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
QualcommQcs405 Firmware-
QualcommQcs405-
QualcommQcs605 Firmware-
QualcommQcs605-
QualcommSd 636 Firmware-
QualcommSd 636-
QualcommSd 665 Firmware-
QualcommSd 665-
QualcommSd 675 Firmware-
QualcommSd 675-
QualcommSd 712 Firmware-
QualcommSd 712-
QualcommSd 710 Firmware-
QualcommSd 710-
QualcommSd 670 Firmware-
QualcommSd 670-
QualcommSd 730 Firmware-
QualcommSd 730-
QualcommSd 820 Firmware-
QualcommSd 820-

References

FAQ

What is CVE-2019-2281?

CVE-2019-2281 is a vulnerability with a CVSS score of 7.8 (HIGH). An unauthenticated bitmap image can be loaded in to memory and subsequently cause execution of unverified code. in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Indu...

How severe is CVE-2019-2281?

CVE-2019-2281 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-2281?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Qcs405 Firmware, Qualcomm Qcs405, Qualcomm Qcs605 Firmware, Qualcomm Qcs605, Qualcomm Sd 636 Firmware.