Buffer overflow in Qualcomm products - CVE-2024-38409

 

Buffer overflow in Qualcomm products - CVE-2024-38409

Published: November 4, 2024


Vulnerability identifier: #VU99679
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38409
CWE-ID: CWE-120
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in WLAN Windows Host. A local application can execute arbitrary code.


Affected software

Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB
WSA8845H
WSA8845
WSA8840
WSA8835
WSA8830
WCN3660B
WCN3620
WCD9385
WCD9380
WCD9375
WCD9370
BB)
FastConnect 6700
Snapdragon 429 Mobile Platform
SC8380XP
Qualcomm Video Collaboration VC3 Platform
QCS6490
QCS5430
QCM6490
QCM5430
QCC2076
QCC2073
FastConnect 7800
FastConnect 6900
SDM429W

How to mitigate CVE-2024-38409

Install security update from vendor's website.


External References

Related Security Bulletins