CVE-2023-28561: Buffer Copy Without Checking Size of Input in QESL
Published Aug 8, 2023
·Updated
Memory corruption in QESL while processing payload from external ESL device to firmware.
Affected Software
4 affected components
All of the following
Qualcomm Qcn7606 Firmware
Qualcomm Qcn7606
Qualcomm Qcn7606 Firmware
Qualcomm Qcn7606
Event History
Aug 8, 2023
CVE Published
via MITRE·09:15 AM
Data Sourced
via MITRE·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-28561?
CVE-2023-28561 is a vulnerability that involves memory corruption in QESL (Qualcomm Enhanced Self-Loader) when processing payload from an external ESL (Embedded Subscriber Line) device to firmware.
2
What is the severity of CVE-2023-28561?
CVE-2023-28561 has a severity rating of 9.8 out of 10, indicating it is a critical vulnerability.
3
Which software is affected by CVE-2023-28561?
Qualcomm Qcn7606 Firmware is affected by CVE-2023-28561.
4
How can I fix CVE-2023-28561?
To fix CVE-2023-28561, it is recommended to apply the patch or update provided by Qualcomm.
5
Where can I find more information about CVE-2023-28561?
You can find more information about CVE-2023-28561 in the August 2023 bulletin on the Qualcomm Product Security website.