Stack-based buffer overflow in Qualcomm products - CVE-2024-38410

 

Stack-based buffer overflow in Qualcomm products - CVE-2024-38410

Published: November 4, 2024


Vulnerability identifier: #VU99680
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38410
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in WLAN Windows Host. A local application can execute arbitrary code.


Affected software

Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB
WSA8845H
WSA8845
WSA8840
WSA8835
WSA8830
WCN3660B
WCN3620
WCD9385
WCD9380
WCD9375
WCD9370
BB)
FastConnect 6700
Snapdragon 429 Mobile Platform
SC8380XP
Qualcomm Video Collaboration VC3 Platform
QCS6490
QCS5430
QCM6490
QCM5430
QCC2076
QCC2073
FastConnect 7800
FastConnect 6900
SDM429W

How to mitigate CVE-2024-38410

Install security update from vendor's website.


External References

Related Security Bulletins