{"id": "CVE-2019-2281", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.6, "accessVector": "LOCAL", "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 3.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 7.8, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 1.8}]}, "published": "2019-07-25T17:15:12.863", "references": [{"url": "https://www.qualcomm.com/company/product-security/bulletins", "tags": ["Vendor Advisory"], "source": "product-security@qualcomm.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "descriptions": [{"lang": "en", "value": "An unauthenticated bitmap image can be loaded in to memory and subsequently cause execution of unverified code. in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in QCS405, QCS605, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SDX24, SXR1130"}, {"lang": "es", "value": "Una imagen de mapa de bits no autenticada se puede cargar en la memoria y, posteriormente, causar la ejecuci\u00f3n de un c\u00f3digo no comprobado. En los productos Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music en las versiones QCS405, QCS605, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SDX24, SXR1130"}], "lastModified": "2020-08-24T17:37:01.140", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:qcs405_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36F5A18B-8C9E-4A38-B994-E3E2696BB83D"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:qcs405:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B703667D-DE09-40AF-BA44-E0E56252A790"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:qcs605_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B05FD66D-13A6-40E9-A64B-E428378F237E"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:qcs605:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D0D665C1-3EBA-42F2-BF56-55E6C365F7DF"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_636_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CE94E380-CB75-462E-B411-BF38F17D53B2"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_636:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0947F38F-3DC2-45F1-B3B3-963922F32054"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_665_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A00C8264-02FC-4191-A4D9-363A99627176"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_665:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "63D21FBC-976A-488A-A329-FBAEB8017C6D"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_675_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3F900C8F-9763-441A-B97E-E5394A68A08A"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_675:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "589C1001-E9F6-41A6-BCC8-A94A3C97F2E6"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_712_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6BFF8872-645F-4A05-BAF9-7797CFBE37C6"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_712:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9CB91AFF-C149-4F5C-92EC-E78E66935528"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_710_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B529780-DB0A-4F9C-AE63-6DEC593B86E5"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_710:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "669E7360-E8C3-4BB8-A3B6-61BD58AFAF62"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_670_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D49606C5-7306-4F33-864C-C1905594F09C"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_670:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B43964AF-7CEC-420A-935B-D3895B2BAC70"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_730_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9F5E6464-2341-40EC-B276-6CE49CF1DFDD"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_730:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "73D9A6B7-2147-4992-ADC3-6A8DE3D3E0A5"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_820_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E077FC03-F86F-417A-A3E6-BC88CB85C6F0"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_820:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E016356C-94ED-4CDD-8351-97D265FE036E"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_835_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CFF35A3-1472-4665-9DAB-1ABC45C0D5B4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_835:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F930E9BF-C502-49C6-8BE8-9A711B89FA1B"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_845_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A2D2B3B-CB28-46AA-9117-A7FA371FDE80"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_845:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DE18BF66-B0DB-48BB-B43A-56F01821F5A3"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_850_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C10C7CB-3B66-4F17-8146-6A85611E2BA9"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_850:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B9DA765F-53DE-4FB0-B825-6C11B3177641"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_855_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "91400943-3D25-4E44-9FFD-9E3076305D80"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_855:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "57B16867-710D-4748-8636-635E2C6F7389"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_8cx_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A71D1A7C-537F-458B-BA56-A11F95E36EA9"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_8cx:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "716DEC4D-D854-44CD-8A14-AA5AFD96809E"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sda660_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A2326BD7-28A5-4244-8501-B109913E7AE6"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sda660:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "532D244B-8B5A-4923-B7F1-9DC0A5FC0E9D"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sdm630_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8EA0D645-80F6-48C3-AF0D-99198ADC8778"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sdm630:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "814FF3F3-CD5A-45A3-988C-6457D2CEB48C"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sdm660_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "24D7B67C-6FEC-48F8-9D46-778E4528BC20"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sdm660:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "05006807-D961-446C-B8DC-C87507F1316E"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sdx24_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F9BE864E-7B1E-44D5-A10A-60078095DE33"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sdx24:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "96DD6B48-2554-464D-A061-DBB4B8E00758"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sxr1130_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "096F7BA5-FF58-416B-93EF-733B16326C86"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sxr1130:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7AF958FB-1611-4102-A2DB-8D4311AE0D72"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "product-security@qualcomm.com"}