7.8

CVE-2024-53022

Memory corruption may occur during communication between primary and guest VM.

Data is provided by the National Vulnerability Database (NVD)
QualcommQam8255p Firmware Version-
   QualcommQam8255p
QualcommQam8295p Firmware Version-
   QualcommQam8295p
QualcommQam8620p Firmware Version-
   QualcommQam8620p
QualcommQam8650p Firmware Version-
   QualcommQam8650p
QualcommQam8775p Firmware Version-
   QualcommQam8775p
QualcommQamsrv1h Firmware Version-
   QualcommQamsrv1h
QualcommQamsrv1m Firmware Version-
   QualcommQamsrv1m
QualcommQca6595 Firmware Version-
   QualcommQca6595
QualcommQca6696 Firmware Version-
   QualcommQca6696
QualcommSa7255p Firmware Version-
   QualcommSa7255p
QualcommSa7775p Firmware Version-
   QualcommSa7775p
QualcommSa8255p Firmware Version-
   QualcommSa8255p
QualcommSa8295p Firmware Version-
   QualcommSa8295p
QualcommSa8540p Firmware Version-
   QualcommSa8540p
QualcommSa8620p Firmware Version-
   QualcommSa8620p
QualcommSa8650p Firmware Version-
   QualcommSa8650p
QualcommSa8770p Firmware Version-
   QualcommSa8770p
QualcommSa8775p Firmware Version-
   QualcommSa8775p
QualcommSa9000p Firmware Version-
   QualcommSa9000p
QualcommSrv1h Firmware Version-
   QualcommSrv1h
QualcommSrv1l Firmware Version-
   QualcommSrv1l
QualcommSrv1m Firmware Version-
   QualcommSrv1m
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.121
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
product-security@qualcomm.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.