#VU84882 Buffer overflow in Qualcomm products - CVE-2023-33025
Published: January 1, 2024
Vulnerability identifier: #VU84882
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2023-33025
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
AR8035
FastConnect 6700
FastConnect 6900
QCA8081
QCA8337
QCM4490
QCN6024
QCN9024
QCS4490
SM4450
Snapdragon 680 4G Mobile Platform
Snapdragon 685 4G Mobile Platform (SM6225-AD)
Snapdragon X65 5G Modem-RF System
Snapdragon X70 Modem-RF System
WCD9370
WCD9375
WCD9380
WCN3950
WCN3988
WSA8810
WSA8815
WSA8830
WSA8835
WSA8832
AR8035
FastConnect 6700
FastConnect 6900
QCA8081
QCA8337
QCM4490
QCN6024
QCN9024
QCS4490
SM4450
Snapdragon 680 4G Mobile Platform
Snapdragon 685 4G Mobile Platform (SM6225-AD)
Snapdragon X65 5G Modem-RF System
Snapdragon X70 Modem-RF System
WCD9370
WCD9375
WCD9380
WCN3950
WCN3988
WSA8810
WSA8815
WSA8830
WSA8835
WSA8832
Software vendor:
Qualcomm
Qualcomm
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation in Data Modem. A remote attacker can execute arbitrary code.
Remediation
Install security update from vendor's website.