SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-10510

BT process died and BT toggled due to null pointer dereference when invalid vendor pass through command sent from remote in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in QCS405, QCS605, SD 636, SD 675, SD 730,…

HIGH 8.2EPSS 0.69%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

BT process died and BT toggled due to null pointer dereference when invalid vendor pass through command sent from remote in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in QCS405, QCS605, SD 636, SD 675, SD 730, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660

CVSS 3.1
8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
EPSS
0.69% probability · 51th percentile
CISA KEV
Not listed
Weakness
CWE-476
Affected
qualcomm/qcs405 firmware · qualcomm/qcs605 firmware · qualcomm/sd 636 firmware · qualcomm/sd 675 firmware · qualcomm/sd 730 firmware · qualcomm/sd 820a firmware · qualcomm/sd 835 firmware · qualcomm/sd 845 firmware · qualcomm/sd 850 firmware · qualcomm/sd 855 firmware · qualcomm/sdm630 firmware · qualcomm/sdm660 firmware
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.