Description
memory corruption when WiFi display APIs are invoked with large random inputs.
Published: 2024-11-04
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-20890 memory corruption when WiFi display APIs are invoked with large random inputs.
History

Thu, 07 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm fastconnect 6900
Qualcomm fastconnect 7800
Qualcomm sdm429w
Qualcomm snapdragon 429 Mobile Platform
Qualcomm snapdragon 8 Gen 1 Mobile Platform
Qualcomm wcd9380
Qualcomm wcn3620
Qualcomm wcn3660b
Qualcomm wsa8830
Qualcomm wsa8835
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sdm429w:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_429_mobile_platform:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_8_gen_1_mobile_platform:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3620:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn3660b:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8830:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8835:-:*:*:*:*:*:*:*
Vendors & Products Qualcomm fastconnect 6900
Qualcomm fastconnect 7800
Qualcomm sdm429w
Qualcomm snapdragon 429 Mobile Platform
Qualcomm snapdragon 8 Gen 1 Mobile Platform
Qualcomm wcd9380
Qualcomm wcn3620
Qualcomm wcn3660b
Qualcomm wsa8830
Qualcomm wsa8835

Mon, 04 Nov 2024 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm fastconnect 6900 Firmware
Qualcomm fastconnect 7800 Firmware
Qualcomm sdm429w Firmware
Qualcomm snapdragon 429 Mobile Platform Firmware
Qualcomm snapdragon 8 Gen 1 Mobile Platform Firmware
Qualcomm wcd9380 Firmware
Qualcomm wcn3620 Firmware
Qualcomm wcn3660b Firmware
Qualcomm wsa8830 Firmware
Qualcomm wsa8835 Firmware
CPEs cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sdm429w_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_429_mobile_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_8_gen_1_mobile_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3620_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3660b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*
Vendors & Products Qualcomm
Qualcomm fastconnect 6900 Firmware
Qualcomm fastconnect 7800 Firmware
Qualcomm sdm429w Firmware
Qualcomm snapdragon 429 Mobile Platform Firmware
Qualcomm snapdragon 8 Gen 1 Mobile Platform Firmware
Qualcomm wcd9380 Firmware
Qualcomm wcn3620 Firmware
Qualcomm wcn3660b Firmware
Qualcomm wsa8830 Firmware
Qualcomm wsa8835 Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 04 Nov 2024 10:15:00 +0000

Type Values Removed Values Added
Description memory corruption when WiFi display APIs are invoked with large random inputs.
Title Improper Input Validation in Video
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Qualcomm Fastconnect 6900 Fastconnect 6900 Firmware Fastconnect 7800 Fastconnect 7800 Firmware Sdm429w Sdm429w Firmware Snapdragon 429 Mobile Platform Snapdragon 429 Mobile Platform Firmware Snapdragon 8 Gen 1 Mobile Platform Snapdragon 8 Gen 1 Mobile Platform Firmware Wcd9380 Wcd9380 Firmware Wcn3620 Wcn3620 Firmware Wcn3660b Wcn3660b Firmware Wsa8830 Wsa8830 Firmware Wsa8835 Wsa8835 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2024-11-16T04:55:28.069Z

Reserved: 2024-01-16T03:27:26.436Z

Link: CVE-2024-23386

cve-icon Vulnrichment

Updated: 2024-11-04T11:11:54.787Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-04T10:15:04.760

Modified: 2024-11-07T19:54:23.047

Link: CVE-2024-23386

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses