CVE-2024-21452: Improper Input Validation in Automotive Telematics
Published Apr 1, 2024
·Updated
Transient DOS while decoding an ASN.1 OER message containing a SEQUENCE of unknown extensions.
Affected Software
12 affected components
All of the following
Qualcomm C-v2x 9150 Firmware
Qualcomm C-v2x 9150
All of the following
Qualcomm Qca6584au Firmware
Qualcomm QCA6584AU
All of the following
Qualcomm Qca6698aq Firmware
Qualcomm Qca6698aq
All of the following
Qualcomm Snapdragon Auto 5g Modem-rf Firmware
Qualcomm Snapdragon Auto 5g Modem-rf
All of the following
Qualcomm Snapdragon Auto 5g Modem-rf Gen 2 Firmware
Qualcomm Snapdragon Auto 5g Modem-rf Gen 2
All of the following
Qualcomm Snapdragon Auto 4g Modem Firmware
Qualcomm Snapdragon Auto 4g Modem
Event History
Apr 1, 2024
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-21452?
CVE-2024-21452 has been rated as a transient Denial of Service vulnerability that arises during the decoding of ASN.1 OER messages.
2
How do I fix CVE-2024-21452?
To mitigate CVE-2024-21452, it is advised to apply the necessary security patches released by Qualcomm for the affected firmware.
3
Which Qualcomm firmware is affected by CVE-2024-21452?
CVE-2024-21452 impacts Qualcomm firmware versions across various products including C-v2x 9150, Qca6584au, Qca6698aq, and Snapdragon Auto series.
4
What could be the potential impact of exploiting CVE-2024-21452?
Exploitation of CVE-2024-21452 may lead to a Denial of Service condition, affecting the availability of the device.
5
Is there an official advisory for CVE-2024-21452?
Yes, Qualcomm has provided a security bulletin addressing CVE-2024-21452 with recommended actions for affected users.