Lucene search

K
cve[email protected]CVE-2023-43517
HistoryFeb 06, 2024 - 6:16 a.m.

CVE-2023-43517

2024-02-0606:16:01
CWE-787
CWE-284
web.nvd.nist.gov
33
cve-2023-43517
memory corruption
automotive multimedia
improper access control
hab
nvd

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Memory corruption in Automotive Multimedia due to improper access control in HAB.

Affected configurations

NVD
Node
qualcommqam8255p_firmwareMatch-
AND
qualcommqam8255pMatch-
Node
qualcommqam8295p_firmwareMatch-
AND
qualcommqam8295pMatch-
Node
qualcommqam8650p_firmwareMatch-
AND
qualcommqam8650pMatch-
Node
qualcommqam8775p_firmwareMatch-
AND
qualcommqam8775pMatch-
Node
qualcommqamsrv1h_firmwareMatch-
AND
qualcommqamsrv1hMatch-
Node
qualcommqamsrv1m_firmwareMatch-
AND
qualcommqamsrv1mMatch-
Node
qualcommqca6574au_firmwareMatch-
AND
qualcommqca6574auMatch-
Node
qualcommqca6595_firmwareMatch-
AND
qualcommqca6595Match-
Node
qualcommqca6696_firmwareMatch-
AND
qualcommqca6696Match-
Node
qualcommqca6698aq_firmwareMatch-
AND
qualcommqca6698aqMatch-
Node
qualcommsa8255p_firmwareMatch-
AND
qualcommsa8255pMatch-
Node
qualcommsa8295p_firmwareMatch-
AND
qualcommsa8295pMatch-
Node
qualcommsa8540p_firmwareMatch-
AND
qualcommsa8540pMatch-
Node
qualcommsa8650p_firmwareMatch-
AND
qualcommsa8650pMatch-
Node
qualcommsa8770p_firmwareMatch-
AND
qualcommsa8770pMatch-
Node
qualcommsa8775p_firmwareMatch-
AND
qualcommsa8775pMatch-
Node
qualcommsa9000p_firmwareMatch-
AND
qualcommsa9000pMatch-
Node
qualcommsrv1h_firmwareMatch-
AND
qualcommsrv1hMatch-
Node
qualcommsrv1m_firmwareMatch-
AND
qualcommsrv1mMatch-

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Snapdragon Auto"
    ],
    "product": "Snapdragon",
    "vendor": "Qualcomm, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "QAM8255P"
      },
      {
        "status": "affected",
        "version": "QAM8295P"
      },
      {
        "status": "affected",
        "version": "QAM8650P"
      },
      {
        "status": "affected",
        "version": "QAM8775P"
      },
      {
        "status": "affected",
        "version": "QAMSRV1H"
      },
      {
        "status": "affected",
        "version": "QAMSRV1M"
      },
      {
        "status": "affected",
        "version": "QCA6574AU"
      },
      {
        "status": "affected",
        "version": "QCA6595"
      },
      {
        "status": "affected",
        "version": "QCA6696"
      },
      {
        "status": "affected",
        "version": "QCA6698AQ"
      },
      {
        "status": "affected",
        "version": "SA8255P"
      },
      {
        "status": "affected",
        "version": "SA8295P"
      },
      {
        "status": "affected",
        "version": "SA8540P"
      },
      {
        "status": "affected",
        "version": "SA8650P"
      },
      {
        "status": "affected",
        "version": "SA8770P"
      },
      {
        "status": "affected",
        "version": "SA8775P"
      },
      {
        "status": "affected",
        "version": "SA9000P"
      },
      {
        "status": "affected",
        "version": "SRV1H"
      },
      {
        "status": "affected",
        "version": "SRV1M"
      }
    ]
  }
]

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for CVE-2023-43517