8.4

CVE-2023-33092

Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QualcommAqt1000 Firmware Version-
   QualcommAqt1000 Version-
QualcommQca6310 Firmware Version-
   QualcommQca6310 Version-
QualcommQca6320 Firmware Version-
   QualcommQca6320 Version-
QualcommQca6391 Firmware Version-
   QualcommQca6391 Version-
QualcommQca6420 Firmware Version-
   QualcommQca6420 Version-
QualcommQca6430 Firmware Version-
   QualcommQca6430 Version-
QualcommQcm4325 Firmware Version-
   QualcommQcm4325 Version-
QualcommQcm4490 Firmware Version-
   QualcommQcm4490 Version-
QualcommQcm5430 Firmware Version-
   QualcommQcm5430 Version-
QualcommQcm6490 Firmware Version-
   QualcommQcm6490 Version-
QualcommQcm8550 Firmware Version-
   QualcommQcm8550 Version-
QualcommQcs4490 Firmware Version-
   QualcommQcs4490 Version-
QualcommQcs5430 Firmware Version-
   QualcommQcs5430 Version-
QualcommQcs6490 Firmware Version-
   QualcommQcs6490 Version-
QualcommQcs7230 Firmware Version-
   QualcommQcs7230 Version-
QualcommQcs8250 Firmware Version-
   QualcommQcs8250 Version-
QualcommQcs8550 Firmware Version-
   QualcommQcs8550 Version-
QualcommSd730 Firmware Version-
   QualcommSd730 Version-
QualcommSd835 Firmware Version-
   QualcommSd835 Version-
QualcommSd855 Firmware Version-
   QualcommSd855 Version-
QualcommSd888 Firmware Version-
   QualcommSd888 Version-
QualcommSg4150p Firmware Version-
   QualcommSg4150p Version-
QualcommSm6250 Firmware Version-
   QualcommSm6250 Version-
QualcommSm7250p Firmware Version-
   QualcommSm7250p Version-
QualcommSm7315 Firmware Version-
   QualcommSm7315 Version-
QualcommSm7325p Firmware Version-
   QualcommSm7325p Version-
QualcommSm8550p Firmware Version-
   QualcommSm8550p Version-
QualcommWcd9326 Firmware Version-
   QualcommWcd9326 Version-
QualcommWcd9335 Firmware Version-
   QualcommWcd9335 Version-
QualcommWcd9340 Firmware Version-
   QualcommWcd9340 Version-
QualcommWcd9341 Firmware Version-
   QualcommWcd9341 Version-
QualcommWcd9370 Firmware Version-
   QualcommWcd9370 Version-
QualcommWcd9375 Firmware Version-
   QualcommWcd9375 Version-
QualcommWcd9380 Firmware Version-
   QualcommWcd9380 Version-
QualcommWcd9385 Firmware Version-
   QualcommWcd9385 Version-
QualcommWcd9390 Firmware Version-
   QualcommWcd9390 Version-
QualcommWcd9395 Firmware Version-
   QualcommWcd9395 Version-
QualcommWcn3615 Firmware Version-
   QualcommWcn3615 Version-
QualcommWcn3660b Firmware Version-
   QualcommWcn3660b Version-
QualcommWcn3680b Firmware Version-
   QualcommWcn3680b Version-
QualcommWcn3950 Firmware Version-
   QualcommWcn3950 Version-
QualcommWcn3980 Firmware Version-
   QualcommWcn3980 Version-
QualcommWcn3988 Firmware Version-
   QualcommWcn3988 Version-
QualcommWcn3990 Firmware Version-
   QualcommWcn3990 Version-
QualcommWcn6740 Firmware Version-
   QualcommWcn6740 Version-
QualcommWsa8810 Firmware Version-
   QualcommWsa8810 Version-
QualcommWsa8815 Firmware Version-
   QualcommWsa8815 Version-
QualcommWsa8830 Firmware Version-
   QualcommWsa8830 Version-
QualcommWsa8832 Firmware Version-
   QualcommWsa8832 Version-
QualcommWsa8835 Firmware Version-
   QualcommWsa8835 Version-
QualcommWsa8840 Firmware Version-
   QualcommWsa8840 Version-
QualcommWsa8845 Firmware Version-
   QualcommWsa8845 Version-
QualcommWsa8845h Firmware Version-
   QualcommWsa8845h Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.188
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
product-security@qualcomm.com 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.