Improper Access Control in Qualcomm products - CVE-2019-10596
Published: May 17, 2025
Vulnerability identifier: #VU109319
CSH Severity:
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:/VI:/VA:/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10596
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows #AV# #AU# to #BASIC_IMPACT#.
The vulnerability exists due to improper input validation in KERNEL. #AV# #AU# can #EXT_IMPACT#.
Affected software
SDM670
SXR2130
SXR1130
SM8250
SM8150
SM7150
SM6150
SDM845
SDM710
SC8180X
Saipan
SA6155P
Rennell
QCS605
Nicobar
SDM850
Bitra
SC7180
QCS610
SXR2130
SXR1130
SM8250
SM8150
SM7150
SM6150
SDM845
SDM710
SC8180X
Saipan
SA6155P
Rennell
QCS605
Nicobar
SDM850
Bitra
SC7180
QCS610
How to mitigate CVE-2019-10596
Install security update from vendor's website.