Crafted image that has a valid signature from a non-QC entity can be loaded which can read/write memory that belongs to the secure world in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, MSM8998, QCS404, QCS605, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SM6150, SM7150, SM8150, SXR1130, SXR2130

Project Subscriptions

Vendors Products
Qualcomm Subscribe
Mdm9205 Subscribe
Mdm9205 Firmware Subscribe
Msm8998 Subscribe
Msm8998 Firmware Subscribe
Qcs404 Firmware Subscribe
Qcs605 Firmware Subscribe
Sda660 Firmware Subscribe
Sda845 Firmware Subscribe
Sdm630 Firmware Subscribe
Sdm636 Firmware Subscribe
Sdm660 Firmware Subscribe
Sdm670 Firmware Subscribe
Sdm710 Firmware Subscribe
Sdm845 Firmware Subscribe
Sdm850 Firmware Subscribe
Sdx24 Firmware Subscribe
Sm6150 Firmware Subscribe
Sm7150 Firmware Subscribe
Sm8150 Firmware Subscribe
Sxr1130 Subscribe
Sxr1130 Firmware Subscribe
Sxr2130 Subscribe
Sxr2130 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-11980 Crafted image that has a valid signature from a non-QC entity can be loaded which can read/write memory that belongs to the secure world in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, MSM8998, QCS404, QCS605, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SM6150, SM7150, SM8150, SXR1130, SXR2130
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2024-08-04T18:49:47.380Z

Reserved: 2018-12-10T00:00:00.000Z

Link: CVE-2019-2338

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-12T09:15:13.300

Modified: 2024-11-21T04:40:44.863

Link: CVE-2019-2338

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses