#VU79023 Untrusted Pointer Dereference in Qualcomm Hardware solutions


Published: 2023-08-07

Vulnerability identifier: #VU79023

Vulnerability risk: High

CVSSv3.1: 7.9 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-21643

CWE-ID: CWE-822

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
APQ8064AU
Mobile applications / Mobile firmware & hardware
QAM8295P
Mobile applications / Mobile firmware & hardware
QCA6564A
Mobile applications / Mobile firmware & hardware
QCA6564AU
Mobile applications / Mobile firmware & hardware
QCA6574A
Mobile applications / Mobile firmware & hardware
QCA6584AU
Mobile applications / Mobile firmware & hardware
QCA6595
Mobile applications / Mobile firmware & hardware
QCA6595AU
Mobile applications / Mobile firmware & hardware
QCA6696
Mobile applications / Mobile firmware & hardware
SA6145P
Mobile applications / Mobile firmware & hardware
SA6150P
Mobile applications / Mobile firmware & hardware
SA6155
Mobile applications / Mobile firmware & hardware
SA8145P
Mobile applications / Mobile firmware & hardware
SA8150P
Mobile applications / Mobile firmware & hardware
SA8155
Mobile applications / Mobile firmware & hardware
SA8155P
Mobile applications / Mobile firmware & hardware
SA8195P
Mobile applications / Mobile firmware & hardware
SA8295P
Mobile applications / Mobile firmware & hardware
APQ8096AU
Hardware solutions / Firmware
MSM8996AU
Hardware solutions / Firmware
QCA6574AU
Hardware solutions / Firmware
SA6155P
Hardware solutions / Firmware
SA8540P
Hardware solutions / Firmware
SA9000P
Hardware solutions / Firmware

Vendor: Qualcomm

Description

The vulnerability allows a remote application to read and manipulate data.

The vulnerability exists due to improper input validation in Automotive. A remote application can read and manipulate data.

Mitigation
Install security update from vendor's website.

Vulnerable software versions

APQ8064AU: All versions

APQ8096AU: All versions

MSM8996AU: All versions

QAM8295P: All versions

QCA6564A: All versions

QCA6564AU: All versions

QCA6574A: All versions

QCA6574AU: All versions

QCA6584AU: All versions

QCA6595: All versions

QCA6595AU: All versions

QCA6696: All versions

SA6145P: All versions

SA6150P: All versions

SA6155: All versions

SA6155P: All versions

SA8145P: All versions

SA8150P: All versions

SA8155: All versions

SA8155P: All versions

SA8195P: All versions

SA8295P: All versions

SA8540P: All versions

SA9000P: All versions


External links
http://docs.qualcomm.com/product/publicresources/securitybulletin/august-2023-bulletin.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability