Improper Authentication in Qualcomm products - CVE-2019-10562
Published: May 17, 2025
Vulnerability identifier: #VU109307
CSH Severity:
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:/VI:/VA:/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10562
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows #AV# #AU# to #BASIC_IMPACT#.
The vulnerability exists due to improper input validation in QTEE. #AV# #AU# can #EXT_IMPACT#.
Affected software
SDM636
SXR2130
SXR1130
SM8250
SM8150
SM7150
SM6150
SDX55
SDX24
SDM845
SDM710
SDM670
SDM660
SDM630
SDA845
SDA660
SA6155P
Rennell
QCS605
Nicobar
MSM8998
Kamorta
SDM850
IPQ6018
SC7180
SA415M
QCS610
QCS404
SXR2130
SXR1130
SM8250
SM8150
SM7150
SM6150
SDX55
SDX24
SDM845
SDM710
SDM670
SDM660
SDM630
SDA845
SDA660
SA6155P
Rennell
QCS605
Nicobar
MSM8998
Kamorta
SDM850
IPQ6018
SC7180
SA415M
QCS610
QCS404
How to mitigate CVE-2019-10562
Install security update from vendor's website.