Buffer over-read in Qualcomm products - CVE-2024-33047
Published: September 2, 2024
Vulnerability identifier: #VU96685
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-33047
CWE-ID: CWE-126
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation in Display. A local application can execute arbitrary code.
Affected software
Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB
WSA8845H
WSA8845
WSA8840
WSA8835
WSA8830
WCN3660B
WCN3620
WCD9385
WCD9380
WCD9375
WCD9370
BB)
FastConnect 6700
Snapdragon 7c+ Gen 3 Compute
Snapdragon 429 Mobile Platform
SC8380XP
Qualcomm Video Collaboration VC3 Platform
QCS6490
QCS5430
QCM6490
QCM5430
FastConnect 7800
FastConnect 6900
SDM429W
WSA8845H
WSA8845
WSA8840
WSA8835
WSA8830
WCN3660B
WCN3620
WCD9385
WCD9380
WCD9375
WCD9370
BB)
FastConnect 6700
Snapdragon 7c+ Gen 3 Compute
Snapdragon 429 Mobile Platform
SC8380XP
Qualcomm Video Collaboration VC3 Platform
QCS6490
QCS5430
QCM6490
QCM5430
FastConnect 7800
FastConnect 6900
SDM429W
How to mitigate CVE-2024-33047
Install security update from vendor's website.