ID

VAR-201907-0562


CVE

CVE-2019-2237


TITLE

plural Snapdragon Error handling vulnerabilities in products

Trust: 0.8

sources: JVNDB: JVNDB-2019-006902

DESCRIPTION

Failure in taking appropriate action to handle the error case If keypad gpio deactivation fails leads to silent failure scenario and subsequent logic gets executed everytime in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MDM9650, MDM9655, QCS605, SD 210/SD 212/SD 205, SD 410/12, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 8CX, SXR1130. plural Snapdragon The product contains an error handling vulnerability.Information may be altered. Qualcomm Closed-Source Components are prone to multiple unspecified vulnerabilities. An attacker can exploit these issues to perform unauthorized actions. This may aid in further attacks. These issues are being tracked by Android Bug IDs A-129766496, A-129766125, A-122473271, A-122474808, A-122472479, A-122473168, A-122473304, A-122473496, A-122473989, A-129766432, A-129766099 and A-129766299. Qualcomm MDM9206 is a central processing unit (CPU) product of Qualcomm (Qualcomm). Security flaws exist in several Qualcomm products. The following products and versions are affected: Qualcomm MDM9206; MDM9607; MDM9650; MDM9655; QCS605; SD 210; SD 212; SD 205; SD 410/12; SD 675; SD 712; SXR1130

Trust: 2.07

sources: NVD: CVE-2019-2237 // JVNDB: JVNDB-2019-006902 // BID: 108986 // VULHUB: VHN-153672 // VULMON: CVE-2019-2237

AFFECTED PRODUCTS

vendor:qualcommmodel:mdm9206scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9655scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 8cxscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qcs605scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 205scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 670scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 212scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sxr1130scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 412scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 730scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 710scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 210scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 675scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9607scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 712scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 410scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9206scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9607scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9650scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9655scope: - version: -

Trust: 0.8

vendor:qualcommmodel:qcs605scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 205scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 210scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 212scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 410scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 412scope: - version: -

Trust: 0.8

vendor:googlemodel:pixel xlscope:eqversion:0

Trust: 0.3

vendor:googlemodel:pixel cscope:eqversion:0

Trust: 0.3

vendor:googlemodel:pixelscope:eqversion:0

Trust: 0.3

vendor:googlemodel:nexus playerscope:eqversion:0

Trust: 0.3

vendor:googlemodel:nexusscope:eqversion:9

Trust: 0.3

vendor:googlemodel:nexus 6pscope: - version: -

Trust: 0.3

vendor:googlemodel:nexusscope:eqversion:6

Trust: 0.3

vendor:googlemodel:nexusscope:eqversion:5x

Trust: 0.3

vendor:googlemodel:androidscope:eqversion:0

Trust: 0.3

sources: BID: 108986 // JVNDB: JVNDB-2019-006902 // NVD: CVE-2019-2237

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-2237
value: MEDIUM

Trust: 1.0

NVD: CVE-2019-2237
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201907-084
value: MEDIUM

Trust: 0.6

VULHUB: VHN-153672
value: LOW

Trust: 0.1

VULMON: CVE-2019-2237
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2019-2237
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-153672
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-2237
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-153672 // VULMON: CVE-2019-2237 // JVNDB: JVNDB-2019-006902 // CNNVD: CNNVD-201907-084 // NVD: CVE-2019-2237

PROBLEMTYPE DATA

problemtype:CWE-388

Trust: 1.9

sources: VULHUB: VHN-153672 // JVNDB: JVNDB-2019-006902 // NVD: CVE-2019-2237

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201907-084

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-201907-084

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-006902

PATCH

title:July 2019 Qualcomm Technologies, Inc. Security Bulletinurl:https://www.qualcomm.com/company/product-security/bulletins

Trust: 0.8

title:Multiple Qualcomm Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=94318

Trust: 0.6

sources: JVNDB: JVNDB-2019-006902 // CNNVD: CNNVD-201907-084

EXTERNAL IDS

db:NVDid:CVE-2019-2237

Trust: 2.9

db:BIDid:108986

Trust: 1.0

db:JVNDBid:JVNDB-2019-006902

Trust: 0.8

db:CNNVDid:CNNVD-201907-084

Trust: 0.7

db:VULHUBid:VHN-153672

Trust: 0.1

db:VULMONid:CVE-2019-2237

Trust: 0.1

sources: VULHUB: VHN-153672 // VULMON: CVE-2019-2237 // BID: 108986 // JVNDB: JVNDB-2019-006902 // CNNVD: CNNVD-201907-084 // NVD: CVE-2019-2237

REFERENCES

url:https://www.qualcomm.com/company/product-security/bulletins

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2019-2237

Trust: 1.4

url:http://code.google.com/android/

Trust: 0.9

url:http://www.qualcomm.com/

Trust: 0.9

url:https://source.android.com/security/bulletin/2019-07-01.html

Trust: 0.9

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-2237

Trust: 0.8

url:https://www.securityfocus.com/bid/108986

Trust: 0.7

url:https://vigilance.fr/vulnerability/google-android-multiple-vulnerabilities-of-july-2019-29673

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/388.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-153672 // VULMON: CVE-2019-2237 // BID: 108986 // JVNDB: JVNDB-2019-006902 // CNNVD: CNNVD-201907-084 // NVD: CVE-2019-2237

CREDITS

The vendor reported these issues.

Trust: 0.9

sources: BID: 108986 // CNNVD: CNNVD-201907-084

SOURCES

db:VULHUBid:VHN-153672
db:VULMONid:CVE-2019-2237
db:BIDid:108986
db:JVNDBid:JVNDB-2019-006902
db:CNNVDid:CNNVD-201907-084
db:NVDid:CVE-2019-2237

LAST UPDATE DATE

2024-11-23T21:37:05.884000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-153672date:2019-07-26T00:00:00
db:VULMONid:CVE-2019-2237date:2019-07-26T00:00:00
db:BIDid:108986date:2019-07-01T00:00:00
db:JVNDBid:JVNDB-2019-006902date:2019-07-30T00:00:00
db:CNNVDid:CNNVD-201907-084date:2019-07-29T00:00:00
db:NVDid:CVE-2019-2237date:2024-11-21T04:40:30.187

SOURCES RELEASE DATE

db:VULHUBid:VHN-153672date:2019-07-25T00:00:00
db:VULMONid:CVE-2019-2237date:2019-07-25T00:00:00
db:BIDid:108986date:2019-07-01T00:00:00
db:JVNDBid:JVNDB-2019-006902date:2019-07-30T00:00:00
db:CNNVDid:CNNVD-201907-084date:2019-07-02T00:00:00
db:NVDid:CVE-2019-2237date:2019-07-25T17:15:12.083