Information exposure in Qualcomm products - CVE-2023-21624

 

Information exposure in Qualcomm products - CVE-2023-21624

Published: July 3, 2023


Vulnerability identifier: #VU77856
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-21624
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation in DSP Services. A local application can gain access to sensitive information.


Affected software

Snapdragon 888 5G Mobile Platform
SW5100P
SW5100
Snapdragon XR2 5G Platform
Snapdragon X55 5G Modem-RF System
Snapdragon Wear 4100+ Platform
Snapdragon W5+ Gen 1 Wearable Platform
Snapdragon 888+ 5G Mobile Platform (SM8350-AC)
WCD9335
Snapdragon 870 5G Mobile Platform (SM8250-AC)
Snapdragon 865+ 5G Mobile Platform (SM8250-AB)
Snapdragon 865 5G Mobile Platform
Snapdragon 835 Mobile PC Platform
Snapdragon 7c+ Gen 3 Compute
Snapdragon 782G Mobile Platform (SM7325-AF)
Snapdragon 780G 5G Mobile Platform
WCN3660B
WSA8835
WSA8830
WSA8815
WSA8810
WCN6740
WCN3990
WCN3980
WCN3680B
Snapdragon 778G+ 5G Mobile Platform (SM7325-AE)
WCN3610
WCD9385
WCD9380
WCD9375
WCD9370
WCD9341
WCD9340
QCA6436
QCA6797AQ
QCA6698AQ
QCA6696
QCA6595AU
QCA6574A
QCA6574
SA6145P
QCA6426
QCA6391
QCA6320
QCA6310
QAM8255P
FastConnect 6900
FastConnect 6800
FastConnect 6700
SA6150P
SA6155
SA8145P
SA8150P
SA8155
SA8155P
SA8195P
SA8255P
SD865 5G
SM7315
SM7325P
Snapdragon 778G 5G Mobile Platform
Pixel
SXR2130
QCS8155
QCA6574AU
SA6155P
SD835
SD888

How to mitigate CVE-2023-21624

Install security update from vendor's website.

Pixel - update to 2023-07-05

External References

Related Security Bulletins