Lucene search

K
vulnrichmentQualcommVULNRICHMENT:CVE-2023-43554
HistoryJul 01, 2024 - 2:17 p.m.

CVE-2023-43554 Improper Restriction of Operations withing the Bounds of a Memory Buffer in DSP Services

2024-07-0114:17:03
CWE-119
qualcomm
github.com
5
memory corruption
dsp services
improper restriction
fastrpc
ioctl handler

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

High

EPSS

0

Percentile

9.5%

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Memory corruption while processing IOCTL handler in FastRPC.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:aqt1000_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "aqt1000_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:fastconnect_6200_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "fastconnect_6200_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:fastconnect_6700_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "fastconnect_6700_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:fastconnect_6800_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "fastconnect_6800_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "fastconnect_6900_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "fastconnect_7800_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:qca6391_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "qca6391_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:qca6420_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "qca6420_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:qca6430_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "qca6430_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:qcm5430_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "qcm5430_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:qcm6490_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "qcm6490_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:qcs5430_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "qcs5430_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:qcs6490_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "qcs6490_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:qualcomm_video_collaboration_vc3_platform_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "qualcomm_video_collaboration_vc3_platform_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:sc8380xp_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "sc8380xp_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wcd9340_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wcd9340_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wcd9341_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wcd9341_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wcd9370_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wcd9370_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wcd9375_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wcd9375_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wcd9380_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wcd9385_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wsa8810_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wsa8810_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wsa8815_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wsa8815_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wsa8830_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wsa8835_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wsa8840_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wsa8845_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wsa8845h_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

High

EPSS

0

Percentile

9.5%

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2023-43554