Vulnerability Name: CVE-2016-10464 (CCN-142755) Assigned: 2017-08-16 Published: 2018-04-04 Updated: 2018-05-02 Summary: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9640, MDM9650, QCA6174A, QCA6574AU, QCA9377, SD 210/SD 212/SD 205, SD 425, SD 600, SD 650/52, SD 808, SD 810, SD 820, and SDX20, lack of input validation for HCI H4 UART packet ID cause system denial of service. CVSS v3 Severity: 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H )6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H )6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): High
CVSS v2 Severity: 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Complete
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Complete
Vulnerability Type: CWE-20 Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2016-10464 Source: BID Type: Third Party Advisory, VDB Entry103671 Source: CCN Type: BID-103671Google Android Multiple Qualcomm Components Multiple Unspecified Security Vulnerabilities Source: CCN Type: Google Web siteAndroid Source: XF Type: UNKNOWNandroid-cve201610464-dos(142755) Source: CCN Type: Android Open Source ProjectAndroid Security Bulletin—April 2018 Source: CONFIRM Type: Vendor Advisoryhttps://source.android.com/security/bulletin/2018-04-01 Vulnerable Configuration: Configuration 1 :cpe:/o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:mdm9206:-:*:*:*:*:*:*:* Configuration 2 :cpe:/o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:mdm9607:-:*:*:*:*:*:*:* Configuration 3 :cpe:/o:qualcomm:mdm9640_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:mdm9640:-:*:*:*:*:*:*:* Configuration 4 :cpe:/o:qualcomm:mdm9650_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:mdm9650:-:*:*:*:*:*:*:* Configuration 5 :cpe:/o:qualcomm:qca6174a_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:qca6174a:-:*:*:*:*:*:*:* Configuration 6 :cpe:/o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:qca6574au:-:*:*:*:*:*:*:* Configuration 7 :cpe:/o:qualcomm:sd_210_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:sd_210:-:*:*:*:*:*:*:* Configuration 8 :cpe:/o:qualcomm:sd_212_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:sd_212:-:*:*:*:*:*:*:* Configuration 9 :cpe:/o:qualcomm:sd_205_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:sd_205:-:*:*:*:*:*:*:* Configuration 10 :cpe:/o:qualcomm:qca9377_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:qca9377:-:*:*:*:*:*:*:* Configuration 11 :cpe:/o:qualcomm:sd_425_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:sd_425:-:*:*:*:*:*:*:* Configuration 12 :cpe:/o:qualcomm:sd_600_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:sd_600:-:*:*:*:*:*:*:* Configuration 13 :cpe:/o:qualcomm:sd_650_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:sd_650:-:*:*:*:*:*:*:* Configuration 14 :cpe:/o:qualcomm:sd_652_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:sd_652:-:*:*:*:*:*:*:* Configuration 15 :cpe:/o:qualcomm:sd_808_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:sd_808:-:*:*:*:*:*:*:* Configuration 16 :cpe:/o:qualcomm:sd_810_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:sd_810:-:*:*:*:*:*:*:* Configuration 17 :cpe:/o:qualcomm:sd_820_firmware:-:*:*:*:*:*:*:* AND cpe:/h:qualcomm:sd_820:-:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/o:google:android:*:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
qualcomm mdm9206 firmware -
qualcomm mdm9206 -
qualcomm mdm9607 firmware -
qualcomm mdm9607 -
qualcomm mdm9640 firmware -
qualcomm mdm9640 -
qualcomm mdm9650 firmware -
qualcomm mdm9650 -
qualcomm qca6174a firmware -
qualcomm qca6174a -
qualcomm qca6574au firmware -
qualcomm qca6574au -
qualcomm sd 210 firmware -
qualcomm sd 210 -
qualcomm sd 212 firmware -
qualcomm sd 212 -
qualcomm sd 205 firmware -
qualcomm sd 205 -
qualcomm qca9377 firmware -
qualcomm qca9377 -
qualcomm sd 425 firmware -
qualcomm sd 425 -
qualcomm sd 600 firmware -
qualcomm sd 600 -
qualcomm sd 650 firmware -
qualcomm sd 650 -
qualcomm sd 652 firmware -
qualcomm sd 652 -
qualcomm sd 808 firmware -
qualcomm sd 808 -
qualcomm sd 810 firmware -
qualcomm sd 810 -
qualcomm sd 820 firmware -
qualcomm sd 820 -
google android *