Buffer over-read in Qualcomm products - CVE-2023-21660

 

Buffer over-read in Qualcomm products - CVE-2023-21660

Published: June 5, 2023


Vulnerability identifier: #VU76870
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-21660
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation in WLAN Firmware. A remote attacker can perform a denial of service (DoS) attack.


Affected software

QCN6132
WSA8832
QCS4490
QCN9274
QCN9100
QCN9074
QCN9072
QCN9070
QCN9024
QCN9022
QCN9000
QCS6490
QCN6122
QCN6024
QCN6023
QCN5164
QCN5154
QCN5152
QCN5124
QCN5122
QCN5052
WCD9370
WSA8835
WSA8830
WSA8815
WSA8810
WCN3950
WCD9385
WCD9380
WCD9375
QCN5024
SXR2230P
SXR1230P
SSG2125P
SSG2115P
Snapdragon AR2 Gen 1 Platform
Snapdragon 8 Gen 1 Mobile Platform
SD 8 Gen1 5G
QCS8550
IPQ6000
IPQ8076A
IPQ8076
IPQ8074A
IPQ8072A
IPQ8071A
IPQ8070A
IPQ6028
IPQ6018
IPQ6010
IPQ8078
IPQ5028
IPQ5010
Immersive Home 318 Platform
Immersive Home 316 Platform
Immersive Home 216 Platform
Immersive Home 214 Platform
FastConnect 7800
FastConnect 6900
FastConnect 6700
QCA8084
QCN5022
QCM6490
QCM4490
QCC2076
QCC2073
QCA9889
QCA9888
QCA8386
QCA8085
CSR8811
QCA8082
QCA8081
QCA8075
QCA4024
IPQ9574
IPQ8174
IPQ8173
IPQ8078A

How to mitigate CVE-2023-21660

Install security update from vendor's website.


External References

Related Security Bulletins