CVE-2019-10608
Summary
| CVE | CVE-2019-10608 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-16 11:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | Information disclosure issue occurs as there is no binding between the secure keypad session and the secure display session that allows user to take control of the REE to stop the secure keypad session and read the keypad input. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, MSM8905, MSM8909 |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Qualcomm | Apq8009 | - | All | All | All |
| Hardware | Qualcomm | Apq8009 | - | All | All | All |
| Operating System | Qualcomm | Apq8009 Firmware | - | All | All | All |
| Operating System | Qualcomm | Apq8009 Firmware | - | All | All | All |
| Hardware | Qualcomm | Msm8905 | - | All | All | All |
| Hardware | Qualcomm | Msm8905 | - | All | All | All |
| Operating System | Qualcomm | Msm8905 Firmware | - | All | All | All |
| Operating System | Qualcomm | Msm8905 Firmware | - | All | All | All |
| Hardware | Qualcomm | Msm8909 | - | All | All | All |
| Hardware | Qualcomm | Msm8909 | - | All | All | All |
| Operating System | Qualcomm | Msm8909 Firmware | - | All | All | All |
| Operating System | Qualcomm | Msm8909 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| April 2020 Bulletin | Qualcomm | CONFIRM | www.qualcomm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.