7.5
CWE
20
Advisory Published
Updated

CVE-2024-21453: Improper Input Validation in Automotive Telematics

First published: Mon Apr 01 2024(Updated: )

Transient DOS while decoding message of size that exceeds the available system memory.

Credit: product-security@qualcomm.com

Affected SoftwareAffected VersionHow to fix
All of
Qualcomm C-V2X 9150
Qualcomm C-V2X 9150 Firmware
All of
Qualcomm QCS410 Firmware
Qualcomm QCS410 Firmware
All of
Qualcomm QCS610 Firmware
Qualcomm QCS610 Firmware
All of
Qualcomm Video Collaboration VC1 Platform Firmware
Qualcomm Video Collaboration VC1 Platform
All of
Qualcomm Video Collaboration VC3 Platform Firmware
Qualcomm Video Collaboration VC3 Platform
All of
Qualcomm Auto 5G Modem-RF Firmware
Qualcomm Auto 5G Modem-RF Firmware
All of
Qualcomm Snapdragon Auto 4G Modem
Qualcomm Snapdragon Auto 4G Modem Firmware
All of
Qualcomm WCD9341
Qualcomm WCD9341 Firmware
All of
Qualcomm WCD9370 Firmware
Qualcomm WCD9370 Firmware
All of
Qualcomm WCN3950 Firmware
Qualcomm WCN3950 Firmware
All of
Qualcomm Wcn3980
Qualcomm WCN3980
All of
Qualcomm WSA8810
Qualcomm WSA8810 Firmware
All of
Qualcomm WSA8815 Firmware
Qualcomm WSA8815 Firmware

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-21453?

    CVE-2024-21453 has been classified as a transient Denial of Service (DoS) vulnerability.

  • How do I fix CVE-2024-21453?

    To mitigate CVE-2024-21453, apply the latest firmware updates provided by Qualcomm.

  • Which devices are affected by CVE-2024-21453?

    CVE-2024-21453 affects various Qualcomm firmware including c-v2x 9150, QCS410, QCS610, and others.

  • What type of attack does CVE-2024-21453 facilitate?

    CVE-2024-21453 facilitates a DoS attack by decoding messages that exceed the available system memory.

  • Is CVE-2024-21453 a requirements issue?

    No, CVE-2024-21453 is related to handling memory allocation when processing messages, not a requirements issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203