Buffer overflow in Qualcomm products - CVE-2023-33025
Published: January 1, 2024
Vulnerability identifier: #VU84882
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-33025
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation in Data Modem. A remote attacker can execute arbitrary code.
Affected software
Snapdragon X65 5G Modem-RF System
WSA8835
WSA8830
WSA8815
WSA8810
WCN3988
WCN3950
WCD9380
WCD9375
WCD9370
Snapdragon X70 Modem-RF System
AR8035
Snapdragon 685 4G Mobile Platform (SM6225-AD)
Snapdragon 680 4G Mobile Platform
SM4450
QCS4490
QCN9024
QCN6024
QCM4490
QCA8337
QCA8081
FastConnect 6900
FastConnect 6700
WSA8832
Google Android
WSA8835
WSA8830
WSA8815
WSA8810
WCN3988
WCN3950
WCD9380
WCD9375
WCD9370
Snapdragon X70 Modem-RF System
AR8035
Snapdragon 685 4G Mobile Platform (SM6225-AD)
Snapdragon 680 4G Mobile Platform
SM4450
QCS4490
QCN9024
QCN6024
QCM4490
QCA8337
QCA8081
FastConnect 6900
FastConnect 6700
WSA8832
Google Android
How to mitigate CVE-2023-33025
Install security update from vendor's website.
Google Android - addressed in versions 11 2024-01-05, 12L 2024-01-05, 12 2024-01-05, 13 2024-01-05, 14 2024-01-05