9.8
CVE-2023-33025
- EPSS 0.21%
- Published 02.01.2024 06:15:08
- Last modified 21.11.2024 08:04:28
- Source product-security@qualcomm.com
- Teams watchlist Login
- Open Login
Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.
Data is provided by the National Vulnerability Database (NVD)
Qualcomm ≫ Ar8035 Firmware Version-
Qualcomm ≫ Fastconnect 6700 Firmware Version-
Qualcomm ≫ Fastconnect 6900 Firmware Version-
Qualcomm ≫ Qca8081 Firmware Version-
Qualcomm ≫ Qca8337 Firmware Version-
Qualcomm ≫ Qcm4490 Firmware Version-
Qualcomm ≫ Qcn6024 Firmware Version-
Qualcomm ≫ Qcn9024 Firmware Version-
Qualcomm ≫ Qcs4490 Firmware Version-
Qualcomm ≫ Sm4450 Firmware Version-
Qualcomm ≫ Snapdragon X70 Modem-rf System Firmware Version-
Qualcomm ≫ Wcd9370 Firmware Version-
Qualcomm ≫ Wcd9375 Firmware Version-
Qualcomm ≫ Wcd9380 Firmware Version-
Qualcomm ≫ Wcn3950 Firmware Version-
Qualcomm ≫ Wcn3988 Firmware Version-
Qualcomm ≫ Wsa8810 Firmware Version-
Qualcomm ≫ Wsa8815 Firmware Version-
Qualcomm ≫ Wsa8830 Firmware Version-
Qualcomm ≫ Wsa8832 Firmware Version-
Qualcomm ≫ Wsa8835 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.21% | 0.434 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
product-security@qualcomm.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.