Security Bulletin
This security bulletin contains one high risk vulnerability.
EUVDB-ID: #VU99674
Risk: High
CVSSv4.0: 6.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2024-38408
CWE-ID:
CWE-310 - Cryptographic Issues
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to read and manipulate data.
The vulnerability exists due to improper input validation in BT Controller. A remote attacker can read and manipulate data.
MitigationInstall update from vendor's website.
Vulnerable software versionsQualcomm Other Drivers for Windows 11 ARM (Version 22H2 or later) - ThinkPad X13s Gen 1 (Type 21BX, 21BY): All versions
Qualcomm Bluetooth Driver for Windows 11 ARM (Version 21H2 or later) - ThinkPad X13s Gen 1 (Type 21BX, 21BY): All versions
Qualcomm Retimer Firmware for Windows 11 ARM (Version 24H2 or later) - ThinkPad T14s Gen 6 (Type 21N1, 21N2): All versions
Qualcomm Integrated System Software and Firmware Package for Windows 11 ARM (Version 24H2 or later) - ThinkPad T14s Gen 6 (Type 21N1, 21N2): All versions
Qualcomm Bluetooth Driver for Windows 10 (Version 2004 or later) - ThinkPad T14s Gen 3 (Type 21BR 21BS), X13 Gen 3 (Type 21BN 21BQ): All versions
Qualcomm NFA765 Bluetooth Filter Driver for Windows 11 (Version 21H2 or later) - ThinkPad L14 Gen 3, L15 Gen 3: All versions
Qualcomm NFA765 Bluetooth Filter Driver for Windows 10 (Version 20H2 or later) - ThinkPad L14 Gen 3, L15 Gen 3: All versions
Qualcomm NFA765/NFA725 Bluetooth Filter Driver for Windows 11 (Version 21H2 or later) - ThinkPad L14 Gen 3, L15 Gen 3: All versions
Qualcomm NFA765/NFA725 Bluetooth Filter Driver for Windows 10 (Version 20H2 or later) - ThinkPad L14 Gen 3, L15 Gen 3: All versions
Qualcomm NFA765 Bluetooth Filter Driver for Windows 11 (Version 21H2 or later) - ThinkPad L13 Gen 3 (Type 21B9, 21BA), L13 Yoga Gen 3 (Type 21BB, 21BC): All versions
ThinkPad X13 Gen 3 21CN: All versions
ThinkPad X13 Gen 3 21CM: All versions
ThinkPad T14s Gen 3 21CR: All versions
ThinkPad T14s Gen 3 21CQ: All versions
ThinkPad S2 Gen 8 Types 21FT China Only: All versions
ThinkPad S2 Gen 7 Type 21BD: All versions
ThinkPad S2 Yoga Gen 8 21FU: All versions
ThinkPad S2 Yoga Gen 7 21BE: All versions
ThinkPad L15 Gen 3 21C8: All versions
ThinkPad L15 Gen 3 21C7: All versions
ThinkPad L14 Gen 3 21C6: All versions
ThinkPad L14 Gen 3 21C5: All versions
ThinkPad L13 Yoga Gen 3 21BC: All versions
ThinkPad L13 Yoga Gen 3 21BB: All versions
ThinkPad L13 Gen 3 21BA: All versions
ThinkPad L13 Gen 3 21B9: All versions
ThinkPad X13s 21BY: All versions
ThinkPad X13s 21BX: All versions
ThinkPad X13 Gen 4 21J4: All versions
ThinkPad X13 Gen 4 21J3: All versions
ThinkPad X13 Gen 2 20XJ: All versions
ThinkPad X13 Gen 2 20XH: All versions
ThinkPad T16 Gen 2 21K8: All versions
ThinkPad T16 Gen 2 21K7: All versions
ThinkPad T14s Gen 6 21N2: All versions
ThinkPad T14s Gen 6 21N1: All versions
ThinkPad T14s Gen 4 21F9: All versions
ThinkPad T14s Gen 4 21F8: All versions
ThinkPad T14s Gen 2 20XG: All versions
ThinkPad T14s Gen 2 20XF: All versions
ThinkPad T14 Gen 5 21MD: All versions
ThinkPad T14 Gen 5 21MC: All versions
ThinkPad T14 Gen 4 21K4: All versions
ThinkPad T14 Gen 4 21K3: All versions
ThinkPad T14 Gen 2 20XL: All versions
ThinkPad T14 Gen 2 20XK: All versions
ThinkPad P16v Gen 1 21FF: All versions
ThinkPad P16v Gen 1 21FE: All versions
ThinkPad P16s Gen 2 21KA: All versions
ThinkPad P16s Gen 2 21K9: All versions
ThinkPad P15v Gen 3 21EM: All versions
ThinkPad P15v Gen 3 21EN: All versions
ThinkPad P14s Gen 5 21MF: All versions
ThinkPad P14s Gen 5 21ME: All versions
ThinkPad P14s Gen 4 21K6: All versions
ThinkPad P14s Gen 4 21K5: All versions
ThinkPad P14s Gen 2 21A1: All versions
ThinkPad P14s Gen 2 21A0: All versions
ThinkPad L16 Gen 1 21L8: All versions
ThinkPad L16 Gen 1 21L7: All versions
ThinkPad L15 Gen 2 20X8: All versions
ThinkPad L15 Gen 2 20X7: All versions
ThinkPad L14 Gen 5 21L6: All versions
ThinkPad L14 Gen 5 21L5: All versions
ThinkPad L14 Gen 2 20X6: All versions
ThinkPad L14 Gen 2 20X5: All versions
ThinkPad X13 Yoga Gen 4 21F3: All versions
ThinkPad X13 Yoga Gen 4 21F2: All versions
ThinkPad X13 Gen 4 21EY: All versions
ThinkPad X13 Gen 4 21EX: All versions
ThinkPad X13 Gen 3 21BQ: All versions
ThinkPad X13 Gen 3 21BN: All versions
ThinkPad T14s Gen 4 21F7: All versions
ThinkPad T14s Gen 4 21F6: All versions
ThinkPad T14s Gen 3 21BS: All versions
ThinkPad T14s Gen 3 21BR: All versions
ThinkPad L15 Gen 3 21C4: All versions
ThinkPad L15 Gen 3 21C3: All versions
ThinkPad L14 Gen 3 21C2: All versions
ThinkPad L14 Gen 3 21C1: All versions
ThinkPad T16 Gen 2 21HJ: All versions
ThinkPad T16 Gen 2 21HH: All versions
ThinkPad T14 Gen 4 21HE: All versions
ThinkPad T14 Gen 4 21HD: All versions
ThinkPad P16s Gen 2 21HL: All versions
ThinkPad P16s Gen 2 21HK: All versions
ThinkPad P14s Gen 4 21HG: All versions
ThinkPad P14s Gen 4 21HF: All versions
ThinkPad T16 Gen 1 21BW: All versions
ThinkPad T16 Gen 1 21BV: All versions
ThinkPad T14 Gen 3 21AJ: All versions
ThinkPad T14 Gen 3 21AH: All versions
ThinkPad P16s Gen 1 21BU: All versions
ThinkPad P16s Gen 1 21BT: All versions
ThinkPad P14s Gen 3 21AL: All versions
ThinkPad P14s Gen 3 21AK: All versions
ThinkPad T16 Gen 1 21CJ: All versions
ThinkPad T16 Gen 1 21CH: All versions
ThinkPad T14 Gen 3 21CG: All versions
ThinkPad T14 Gen 3 21CF: All versions
ThinkPad P16s Gen 1 21CL: All versions
ThinkPad P16s Gen 1 21CK: All versions
ThinkPad P14s Gen 3 21J6: All versions
ThinkPad P14s Gen 3 21J5: All versions
ThinkPad L13 Yoga Gen 4 21FS: All versions
ThinkPad L13 Yoga Gen 4 21FR: All versions
ThinkPad L13 Gen 4 21FQ: All versions
ThinkPad L13 Gen 4 21FN: All versions
ThinkPad Z16 Gen 1 21D5: All versions
ThinkPad Z16 Gen 1 21D4: All versions
ThinkPad Z13 Gen 1 21D3: All versions
ThinkPad Z13 Gen 1 21D2: All versions
Qualcomm Bluetooth Driver for Windows 10 (Version 21H2 or later) - ThinkPad Z13 (Type 21D2, 21D3), Z16 (Type 21D4, 21D5): before 1.0.0.1737
Qualcomm Bluetooth Driver for Windows 11 (Version 21H2 or later) - ThinkPad Z13 (Type 21D2, 21D3), Z16 (Type 21D4, 21D5): before 2.0.0.1277
Qualcomm Bluetooth Driver for Windows 11 (Version 21H2 or later) - ThinkPad X13 Gen 4 (Type 21J3, 21J4): before 2.0.0.1229
Qualcomm Bluetooth Driver for Windows 10 (Version 21H2 or later) - ThinkPad X13 Gen 4 (Type 21J3, 21J4): before 1.0.0.1694
Qualcomm Bluetooth Driver for Windows 11 (Version 21H2 or later) - ThinkPad P16v Gen 1 (Type 21FE, 21FF): before 1.0.0.1694
Qualcomm Bluetooth Driver for Windows 10 (Version 21H2 or later) - ThinkPad P16v Gen 1 (Type 21FE, 21FF): before 2.0.0.1229
Qualcomm Bluetooth Driver for Windows 11 (Version 21H2 or later) - ThinkPad P15v Gen 3 (Type 21EM, 21EN): before 2.0.0.1215
Qualcomm Bluetooth Driver for Windows 10 (Version 2004 or later) - ThinkPad P15v Gen 3 (Type 21EM, 21EN): before 1.0.0.1688
Qualcomm Bluetooth Driver for Windows 10 64-bit (Version 21H2 or later) - ThinkPad: before 2.0.0.1229
Qualcomm Bluetooth Driver for Windows 11 (Version 22H2 or later) - ThinkPad: before 2.0.0.1221
Qualcomm Bluetooth Driver for Windows 10 (Version 21H2 or later) - ThinkPad: before 2.0.0.1221
Qualcomm Bluetooth Driver for Windows 10 (Version 2004 or later) - ThinkPad T14 Gen 3, T16 Gen 1, P14s Gen 3, P16s, Gen 1: before 1.0.0.1688
Qualcomm Bluetooth Driver for Windows 10 (Version 21H2 or later) - ThinkPad L14 Gen 5 (Type 21L5, 21L6), L16 Gen 1 (Type 21L7 21L8): before 2.0.0.1229
Qualcomm Bluetooth Driver for Windows 10 (Version 2004 or later) - ThinkPad: before 1.0.0.1694
Qualcomm NFA765 Bluetooth Filter Driver for Windows 11 (Version 21H2 or later) - ThinkPad L13 Gen 4 (Type 21FN, 21FQ), L13 Yoga Gen 4 (Type 21FR, 21FS): before 2.0.0.1229
Qualcomm NFA765 Bluetooth Filter Driver for Windows 10 64-bit (Version 21H2 or later) - ThinkPad L13 Gen 4 (Type 21FN, 21FQ), L13 Yoga Gen 4 (Type 21FR, 21FS): before 2.0.0.1229
Qualcomm Bluetooth Driver for Windows 11 (Version 21H2 or later) - ThinkPad: before 2.0.0.1229
Qualcomm Bluetooth Driver for Windows 11 (Version 22H2 or later) - ThinkPad L14 Gen 5 (Type 21L5, 21L6), L16 Gen 1 (Type 21L7 21L8): before 2.0.0.1229
CPE2.3https://support.lenovo.com/us/en/product_security/LEN-170985
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.