7.8

CVE-2023-33046

Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.

Data is provided by the National Vulnerability Database (NVD)
QualcommAr8035 Firmware Version-
   QualcommAr8035 Version-
QualcommQam8295p Firmware Version-
   QualcommQam8295p Version-
QualcommQca6391 Firmware Version-
   QualcommQca6391 Version-
QualcommQca6574au Firmware Version-
   QualcommQca6574au Version-
QualcommQca6595 Firmware Version-
   QualcommQca6595 Version-
QualcommQca6696 Firmware Version-
   QualcommQca6696 Version-
QualcommQca6698aq Firmware Version-
   QualcommQca6698aq Version-
QualcommQca8081 Firmware Version-
   QualcommQca8081 Version-
QualcommQca8337 Firmware Version-
   QualcommQca8337 Version-
QualcommQcm8550 Firmware Version-
   QualcommQcm8550 Version-
QualcommQcn6024 Firmware Version-
   QualcommQcn6024 Version-
QualcommQcn9011 Firmware Version-
   QualcommQcn9011 Version-
QualcommQcn9012 Firmware Version-
   QualcommQcn9012 Version-
QualcommQcn9024 Firmware Version-
   QualcommQcn9024 Version-
QualcommQcs7230 Firmware Version-
   QualcommQcs7230 Version-
QualcommQcs8250 Firmware Version-
   QualcommQcs8250 Version-
QualcommQcs8550 Firmware Version-
   QualcommQcs8550 Version-
QualcommQrb5165m Firmware Version-
   QualcommQrb5165m Version-
QualcommQrb5165n Firmware Version-
   QualcommQrb5165n Version-
QualcommSa8295p Firmware Version-
   QualcommSa8295p Version-
QualcommSa8540p Firmware Version-
   QualcommSa8540p Version-
QualcommSa9000p Firmware Version-
   QualcommSa9000p Version-
QualcommSg8275p Firmware Version-
   QualcommSg8275p Version-
QualcommSm8550p Firmware Version-
   QualcommSm8550p Version-
QualcommSsg2115p Firmware Version-
   QualcommSsg2115p Version-
QualcommSsg2125p Firmware Version-
   QualcommSsg2125p Version-
QualcommSxr1230p Firmware Version-
   QualcommSxr1230p Version-
QualcommSxr2230p Firmware Version-
   QualcommSxr2230p Version-
QualcommWcd9380 Firmware Version-
   QualcommWcd9380 Version-
QualcommWcd9385 Firmware Version-
   QualcommWcd9385 Version-
QualcommWcd9390 Firmware Version-
   QualcommWcd9390 Version-
QualcommWcd9395 Firmware Version-
   QualcommWcd9395 Version-
QualcommWsa8830 Firmware Version-
   QualcommWsa8830 Version-
QualcommWsa8832 Firmware Version-
   QualcommWsa8832 Version-
QualcommWsa8835 Firmware Version-
   QualcommWsa8835 Version-
QualcommWsa8840 Firmware Version-
   QualcommWsa8840 Version-
QualcommWsa8845 Firmware Version-
   QualcommWsa8845 Version-
QualcommWsa8845h Firmware Version-
   QualcommWsa8845h Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.02% 0.028
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
product-security@qualcomm.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.