Improper permissions in XBL_SEC region enable user to update XBL_SEC code and data and divert the RAM dump path to normal cold boot path in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, MSM8998, QCS404, QCS605, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SM8150, SXR1130, SXR2130

Project Subscriptions

Vendors Products
Qualcomm Subscribe
Kamorta Subscribe
Kamorta Firmware Subscribe
Msm8998 Subscribe
Msm8998 Firmware Subscribe
Qcs404 Firmware Subscribe
Qcs605 Firmware Subscribe
Sda660 Firmware Subscribe
Sda845 Firmware Subscribe
Sdm630 Firmware Subscribe
Sdm636 Firmware Subscribe
Sdm660 Firmware Subscribe
Sdm670 Firmware Subscribe
Sdm710 Firmware Subscribe
Sdm845 Firmware Subscribe
Sdm850 Firmware Subscribe
Sm8150 Firmware Subscribe
Sxr1130 Subscribe
Sxr1130 Firmware Subscribe
Sxr2130 Subscribe
Sxr2130 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-5311 Improper permissions in XBL_SEC region enable user to update XBL_SEC code and data and divert the RAM dump path to normal cold boot path in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, MSM8998, QCS404, QCS605, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SM8150, SXR1130, SXR2130
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2024-08-05T00:05:44.183Z

Reserved: 2019-07-19T00:00:00.000Z

Link: CVE-2019-14054

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-06-02T15:15:10.993

Modified: 2024-11-21T04:25:59.637

Link: CVE-2019-14054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses