Unknown
CVE-2019-2255
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
An unprivileged user can craft a bitstream such that the payload encoded in the bitstream gains code execution in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016, SXR1130
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- msm8909w firmware -,
- msm8996au firmware -,
- qcs605 firmware -,
- qm215 firmware -,
- sd 205 firmware -,
- sd 210 firmware -,
- sd 212 firmware -,
- sd 425 firmware -,
- sd 427 firmware -,
- sd 429 firmware -,
- sd 430 firmware -,
- sd 435 firmware -,
- sd 439 firmware -,
- sd 450 firmware -,
- sd 625 firmware -,
- sd 632 firmware -,
- sd 636 firmware -,
- sd 670 firmware -,
- sd 675 firmware -,
- sd 710 firmware -,
- sd 712 firmware -,
- sd 730 firmware -,
- sd 820 firmware -,
- sd 820a firmware -,
- sd 835 firmware -,
- sd 845 firmware -,
- sd 850 firmware -,
- sd 855 firmware -,
- sd 8cx firmware -,
- sda660 firmware -,
- sdm439 firmware -,
- sdm630 firmware -,
- sdm660 firmware -,
- snapdragon high med 2016 firmware -,
- sxr1130 firmware -
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: