CVE-2016-10434 describes an authentication bypass vulnerability in Qualcomm Snapdragon Automobile and Mobile SD 820/820A processors, affecting Android devices with security patch levels prior to 2018-04-05. The flaw allows an attacker to trigger various error conditions in the RPMB write response function before the input buffer is properly authenticated via HMAC. This vulnerability carries a CVSS v3 score of 7.5 (HIGH), indicating a network-exploitable issue with low attack complexity and high confidentiality impact, though integrity and availability are not affected. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:sd_820_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:sd_820a_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.