6.1

CVE-2024-38425

Information disclosure while sending implicit broadcast containing APP launch information.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QualcommWsa8835 Firmware Version-
   QualcommWsa8835 Version-
QualcommWsa8830 Firmware Version-
   QualcommWsa8830 Version-
QualcommWcd9380 Firmware Version-
   QualcommWcd9380 Version-
QualcommSm8750 Firmware Version-
   QualcommSm8750 Version-
QualcommSm8635 Firmware Version-
   QualcommSm8635 Version-
QualcommSm7435 Firmware Version-
   QualcommSm7435 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.04
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
product-security@qualcomm.com 6.1 1.8 4.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CWE-285 Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.