Improper input validation in Qualcomm products - CVE-2024-21473

 

Improper input validation in Qualcomm products - CVE-2024-21473

Published: April 1, 2024 / Updated: August 26, 2024


Vulnerability identifier: #VU87918
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21473
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in WIN SON. A remote attacker can execute arbitrary code.


Affected software

QCN5021
QCN6100
QCN6024
QCN6023
QCN5550
QCN5502
QCN5164
QCN5154
QCN5152
QCN5124
QCN5122
QCN5064
QCN5054
QCN5052
QCN5024
QCN5022
QCN6102
QCF8001
QCF8000
QCC710
QCA9994
QCA9992
QCA9990
QCA9988
QCA9986
QCA9985
QCA9984
QCA9898
QCA9889
QCA9888
QCA9886
QCN9024
WCD9380
WCD9340
Snapdragon X75 5G Modem-RF System
Snapdragon X65 5G Modem-RF System
SDX65M
QFW7124
QFW7114
QFE1952
QFE1922
QCN9274
QCN9100
QCN9074
QCN9072
QCN9070
QCA9880
QCN9022
QCN9012
QCN9003
QCN9002
QCN9001
QCN9000
QCN6432
QCN6422
QCN6412
QCN6402
QCN6274
QCN6224
QCN6122
QCN6112
IPQ5028
IPQ8071A
IPQ8071
IPQ8070A
IPQ8070
IPQ8068
IPQ8065
IPQ6028
IPQ6018
IPQ6010
IPQ6000
IPQ5332
IPQ5312
IPQ5302
IPQ5300
IPQ8072
IPQ5010
IPQ4029
IPQ4028
IPQ4018
Immersive Home 326 Platform
Immersive Home 3210 Platform
Immersive Home 318 Platform
Immersive Home 316 Platform
Immersive Home 216 Platform
Immersive Home 214 Platform
FastConnect 7800
FastConnect 6900
CSR8811
AR9380
QCA0000
QCA9563
QCA8386
QCA8337
QCA8085
QCA8084
QCA8082
QCA8081
QCA8075
QCA8072
QCA7500
QCA6438
QCA6428
QCA4024
AR8035
PMP8074
IPQ9574
IPQ9570
IPQ9554
IPQ9008
IPQ8174
IPQ8173
IPQ8078A
IPQ8078
IPQ8076A
IPQ8076
IPQ8074A
IPQ8072A
QCA9980
SDX55
QCN6132
IPQ8064
IPQ4019
QCA9558
QCA9531
IPQ8074

How to mitigate CVE-2024-21473

Install security update from vendor's website.


External References

Related Security Bulletins