Buffer over-read in Qualcomm products - CVE-2023-33058
Published: February 5, 2024
Vulnerability identifier: #VU86100
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2023-33058
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Qualcomm
Affected software:
AR8035
FastConnect 6700
FastConnect 6900
FastConnect 7800
QCA6584AU
QCA6698AQ
QCA8081
QCA8337
QCC710
QCM4490
QCM8550
QCN6024
QCN6224
QCN6274
QCN9024
QCS4490
QCS8550
QFW7114
QFW7124
SG8275P
SM8550P
Snapdragon 4 Gen 2 Mobile Platform
Snapdragon 8 Gen 1 Mobile Platform
Snapdragon 8 Gen 2 Mobile Platform
Snapdragon 8 Gen 3 Mobile Platform
Snapdragon 8+ Gen 1 Mobile Platform
Snapdragon 8+ Gen 2 Mobile Platform
Snapdragon Auto 5G Modem-RF Gen 2
Snapdragon X65 5G Modem-RF System
Snapdragon X70 Modem-RF System
Snapdragon X75 5G Modem-RF System
WCD9340
WCD9370
WCD9380
WCD9385
WCD9390
WCD9395
WCN3950
WCN3988
WSA8810
WSA8815
WSA8830
WSA8835
WSA8840
WSA8845
WSA8845H
WSA8832
AR8035
FastConnect 6700
FastConnect 6900
FastConnect 7800
QCA6584AU
QCA6698AQ
QCA8081
QCA8337
QCC710
QCM4490
QCM8550
QCN6024
QCN6224
QCN6274
QCN9024
QCS4490
QCS8550
QFW7114
QFW7124
SG8275P
SM8550P
Snapdragon 4 Gen 2 Mobile Platform
Snapdragon 8 Gen 1 Mobile Platform
Snapdragon 8 Gen 2 Mobile Platform
Snapdragon 8 Gen 3 Mobile Platform
Snapdragon 8+ Gen 1 Mobile Platform
Snapdragon 8+ Gen 2 Mobile Platform
Snapdragon Auto 5G Modem-RF Gen 2
Snapdragon X65 5G Modem-RF System
Snapdragon X70 Modem-RF System
Snapdragon X75 5G Modem-RF System
WCD9340
WCD9370
WCD9380
WCD9385
WCD9390
WCD9395
WCN3950
WCN3988
WSA8810
WSA8815
WSA8830
WSA8835
WSA8840
WSA8845
WSA8845H
WSA8832
Detailed vulnerability description
The vulnerability allows a remote attacker to read and manipulate data.
The vulnerability exists due to improper input validation in Modem. A remote attacker can read and manipulate data.
How to mitigate CVE-2023-33058
Install security update from vendor's website.