CVE-2019-10481
Status: ModifiedHigh (7.8)—
Out of bound access occurs while handling the WMI FW event due to lack of check of buffer argument which comes directly from the WLAN FW in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8096AU, IPQ4019, IPQ8064, IPQ8074, MDM9607, MSM8996AU, QCA6574AU, QCA8081, QCN7605, SDX55, SM6150, SM7150, SM8150
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Base score: 7.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.20%
- Percentile among all scored CVEs: 9
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (13)
Qualcomm — Apq8096au FirmwareQualcomm — Ipq4019 FirmwareQualcomm — Ipq8064 FirmwareQualcomm — Ipq8074 FirmwareQualcomm — Mdm9607 FirmwareQualcomm — Msm8996au FirmwareQualcomm — Qca6574au FirmwareQualcomm — Qca8081 FirmwareQualcomm — Qcn7605 FirmwareQualcomm — Sdx55 FirmwareQualcomm — Sm6150 FirmwareQualcomm — Sm7150 FirmwareQualcomm — Sm8150 Firmware
CWEs
- CWE-129
References
Raw JSON (NVD)
Show
{
"id": "CVE-2019-10481",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "product-security@qualcomm.com",
"affectedData": [
{
"vendor": "Qualcomm, Inc.",
"product": "Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking",
"versions": [
{
"status": "affected",
"version": "APQ8096AU, IPQ4019, IPQ8064, IPQ8074, MDM9607, MSM8996AU, QCA6574AU, QCA8081, QCN7605, SDX55, SM6150, SM7150, SM8150"
}
]
}
]
}
],
"published": "2019-12-18T06:15:11.080",
"references": [
{
"url": "https://www.qualcomm.com/company/product-security/bulletins/december-2019-bulletin",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "product-security@qualcomm.com"
},
{
"url": "https://www.qualcomm.com/company/product-security/bulletins/december-2019-bulletin",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-129"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Out of bound access occurs while handling the WMI FW event due to lack of check of buffer argument which comes directly from the WLAN FW in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8096AU, IPQ4019, IPQ8064, IPQ8074, MDM9607, MSM8996AU, QCA6574AU, QCA8081, QCN7605, SDX55, SM6150, SM7150, SM8150"
},
{
"lang": "es",
"value": "Un acceso fuera del límite se presenta mientras se maneja el evento WMI FW debido a una falta de comprobación del argumento del búfer que proviene directamente del WLAN FW en los productos Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking en las versiones APQ8096AU, IPQ4019, IPQ8064, IPQ8074, MDM9607, MSM8996AU, QCA6574AU, QCA8081, QCN7605, SDX55, SM6150, SM7150, SM8150."
}
],
"lastModified": "2026-06-17T02:11:01.480",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:apq8096au_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DD17C0A3-A200-4659-968B-B2DA03CB683F"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:apq8096au:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B1F31FFB-982A-4308-82F8-C2480DABDED8"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:ipq4019_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "94CB547F-0078-47CD-B511-06DE96882D5A"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:ipq4019:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "AA679375-BB14-4B24-8AD9-B2BFBACE2FDB"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:ipq8064_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A1CC1C1-F2CA-4C43-B9E9-1288C3496C7B"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:ipq8064:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "AC82552A-9E7C-4A13-B7A5-43CEA218675C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:ipq8074_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2914BF98-E69C-4C8D-8B10-759642ADD7B4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:ipq8074:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2118C404-402F-463C-8160-3CC3B703DF30"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A35FECFB-60AE-42A8-BCBB-FEA7D5826D49"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:mdm9607:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E9765187-8653-4D66-B230-B2CE862AC5C0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:msm8996au_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8CA1E7B0-782B-4757-B118-802943798984"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:msm8996au:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "95CB08EC-AE12-4A54-AA3C-998F01FC8763"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D527E2B1-2A46-4FBA-9F7A-F5543677C8FB"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:qca6574au:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8374DDB3-D484-4141-AE0C-42333D2721F6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:qca8081_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D1C53DC-D2F3-4C92-9725-9A85340AF026"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:qca8081:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "ED0585FF-E390-46E8-8701-70964A4057BB"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:qcn7605_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C9D1966-30F0-414D-BE75-0A14B12A1457"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:qcn7605:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "CD28C87D-1D28-4C84-BFE4-56EE3BF2C6B0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sdx55_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E93FB34B-3674-404D-9687-E092E9A246AB"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sdx55:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F3FF5A9A-A34A-499C-B6E0-D67B496C5454"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sm6150_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8ABE492A-3755-4969-9DEB-4B85EBB84644"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sm6150:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E3D3787B-6ACC-4591-B041-01307ED66C36"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sm7150_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F63A748F-2236-4486-83F1-DE4BCBE5D56D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sm7150:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "184F3DFC-27E8-48AC-B46C-C589DBCBF030"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sm8150_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9286B1E8-E39F-4DAA-8969-311CA2A0A8AA"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sm8150:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "19B9AE36-87A9-4EE7-87C8-CCA2DCF51039"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "product-security@qualcomm.com"
}