7.8
CVSSv3

CVE-2019-14047

Published: 22/06/2020 Updated: 26/06/2020
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to the IPA HW commit list in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8053, APQ8096AU, MDM9607, MSM8909W, MSM8996, MSM8996AU, QCN7605, QCS605, SC8180X, SDA845, SDX20, SDX24, SDX55, SM8150, SXR1130

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qualcomm apq8053_firmware -

qualcomm apq8096au_firmware -

qualcomm mdm9607_firmware -

qualcomm msm8909w_firmware -

qualcomm msm8996_firmware -

qualcomm msm8996au_firmware -

qualcomm qcn7605_firmware -

qualcomm qcs605_firmware -

qualcomm sc8180x_firmware -

qualcomm sda845_firmware -

qualcomm sdx20_firmware -

qualcomm sdx24_firmware -

qualcomm sdx55_firmware -

qualcomm sm8150_firmware -

qualcomm sxr1130_firmware -