CVE-2019-14047
While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to the IPA HW commit list in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to the IPA HW commit list in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8053, APQ8096AU, MDM9607, MSM8909W, MSM8996, MSM8996AU, QCN7605, QCS605, SC8180X, SDA845, SDX20, SDX24, SDX55, SM8150, SXR1130
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.21% probability · 12th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- qualcomm/apq8053 firmware · qualcomm/apq8096au firmware · qualcomm/mdm9607 firmware · qualcomm/msm8909w firmware · qualcomm/msm8996 firmware · qualcomm/msm8996au firmware · qualcomm/qcn7605 firmware · qualcomm/qcs605 firmware · qualcomm/sc8180x firmware · qualcomm/sda845 firmware · qualcomm/sdx20 firmware · qualcomm/sdx24 firmware · qualcomm/sdx55 firmware · qualcomm/sm8150 firmware · qualcomm/sxr1130 firmware
- Source
- product-security@qualcomm.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.