Improper Access Control in Qualcomm products - CVE-2019-10596
Published: May 17, 2025
Vulnerability identifier: #VU109319
CSH Severity:
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:/VI:/VA:/SC:N/SI:N/SA:N/E:U/U:
CVE-ID: CVE-2019-10596
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Qualcomm
Affected software:
Bitra
QCS610
SC7180
SDM850
Nicobar
QCS605
Rennell
SA6155P
Saipan
SC8180X
SDM670
SDM710
SDM845
SM6150
SM7150
SM8150
SM8250
SXR1130
SXR2130
Bitra
QCS610
SC7180
SDM850
Nicobar
QCS605
Rennell
SA6155P
Saipan
SC8180X
SDM670
SDM710
SDM845
SM6150
SM7150
SM8150
SM8250
SXR1130
SXR2130
Detailed vulnerability description
The vulnerability allows #AV# #AU# to #BASIC_IMPACT#.
The vulnerability exists due to improper input validation in KERNEL. #AV# #AU# can #EXT_IMPACT#.
How to mitigate CVE-2019-10596
Install security update from vendor's website.