LiveActive security incident?Get immediate response
CVE Record

CVE-2019-14123: Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we conside...

Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we consider widevine HLOS client as non-trustable in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This is a Qualcomm Snapdragon memory-safety issue tied to the Widevine HLOS client trust boundary. Missing bounds checks could cause buffer overflow or over-read on listed Qualcomm platforms. The source bundle does not provide severity, CVSS, exploit prerequisites, or confirmed impact, so urgency depends on whether affected chipsets exist in managed devices.

Executive priority

Set priority after confirming asset exposure. Without known active exploitation or severity, this is not enough evidence for emergency response, but affected Snapdragon fleets should enter firmware review and patch planning because memory-safety issues in device firmware can be hard to detect after compromise.

Technical view

CVE-2019-14123 describes possible buffer overflow and over-read from missing bounds checks against fixed limits when the Widevine HLOS client is treated as non-trustable. Affected Qualcomm product lines include Snapdragon Auto, Compute, Mobile, and Wired Infrastructure and Networking for Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, and SXR2130.

Likely exposure

Exposure is most likely in devices, embedded systems, or infrastructure products using the listed Qualcomm Snapdragon platforms and firmware lineage. The sources do not identify specific OEM device models, operating systems, app-level exposure, or whether remote interaction is possible.

Exploitation context

The provided sources do not report active exploitation, and the CVE is not flagged in KEV. They also do not provide exploitability details, privileges required, attack vector, or proof-of-concept status. Treat exploitation context as unconfirmed pending Qualcomm or OEM guidance.

Researcher notes

Key gaps are CVSS, CWE mapping, attack vector, privilege requirements, affected firmware versions, OEM mappings, and fixed builds. The phrase about treating the Widevine HLOS client as non-trustable suggests a trust-boundary validation issue, but the sources do not provide enough detail to infer a reliable exploit path.

Mitigation direction

  • Check Qualcomm and OEM security bulletins for firmware updates covering CVE-2019-14123.
  • Inventory devices using the listed Qualcomm chipsets or Snapdragon product lines.
  • Prioritize managed mobile, embedded, automotive, and networking assets with affected Qualcomm firmware.
  • Apply vendor-approved firmware or OS updates when available.
  • Monitor Qualcomm and OEM advisories for revised severity or remediation details.

Validation and detection

  • Match device hardware inventories against Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, and SXR2130.
  • Confirm firmware build dates and vendor patch bulletins for each affected device family.
  • Check MDM, EDR, or asset platforms for Qualcomm chipset and firmware metadata.
  • Document devices with unknown chipset lineage for OEM confirmation.
  • Track whether Qualcomm or OEMs publish CVSS, impact, or exploitability updates.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2019-14123 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Qualcomm, Inc.Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and NetworkingKamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.