9.8
CVE-2023-28581
- EPSS 0.13%
- Published 05.09.2023 07:15:14
- Last modified 21.11.2024 07:55:35
- Source product-security@qualcomm.com
- Teams watchlist Login
- Open Login
Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE.
Data is provided by the National Vulnerability Database (NVD)
Qualcomm ≫ Fastconnect 6800 Firmware Version-
Qualcomm ≫ Fastconnect 6900 Firmware Version-
Qualcomm ≫ Fastconnect 7800 Firmware Version-
Qualcomm ≫ Qca6391 Firmware Version-
Qualcomm ≫ Qca6426 Firmware Version-
Qualcomm ≫ Qca6436 Firmware Version-
Qualcomm ≫ Sd 8 Gen1 5g Firmware Version-
Qualcomm ≫ Sd865 5g Firmware Version-
Qualcomm ≫ Snapdragon 8 Gen 1 Firmware Version-
Qualcomm ≫ Snapdragon 865 5g Firmware Version-
Qualcomm ≫ Snapdragon 865+ 5g Firmware Version-
Qualcomm ≫ Snapdragon 870 5g Firmware Version-
Qualcomm ≫ Snapdragon Ar2 Gen 1 Firmware Version-
Qualcomm ≫ Snapdragon Xr2 5g Firmware Version-
Qualcomm ≫ Ssg2115p Firmware Version-
Qualcomm ≫ Ssg2125p Firmware Version-
Qualcomm ≫ Sxr1230p Firmware Version-
Qualcomm ≫ Sxr2230p Firmware Version-
Qualcomm ≫ Wcd9380 Firmware Version-
Qualcomm ≫ Wcd9385 Firmware Version-
Qualcomm ≫ Wcn6740 Firmware Version-
Qualcomm ≫ Wsa8810 Firmware Version-
Qualcomm ≫ Wsa8815 Firmware Version-
Qualcomm ≫ Wsa8830 Firmware Version-
Qualcomm ≫ Wsa8832 Firmware Version-
Qualcomm ≫ Wsa8835 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.13% | 0.336 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
product-security@qualcomm.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.