CVE-2024-21454: Integer Overflow to Buffer Overflow in Automotive Telematics
Published Apr 1, 2024
·Updated
Transient DOS while decoding the ToBeSignedMessage in Automotive Telematics.
Affected Software
6 affected components
All of the following
Qualcomm C-v2x 9150 Firmware
Qualcomm C-v2x 9150
All of the following
Qualcomm Auto 5g Modem-rf Firmware
Qualcomm Auto 5g Modem-rf
All of the following
Qualcomm Auto 4g Modem Firmware
Qualcomm Auto 4g Modem
Event History
Apr 1, 2024
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-21454?
CVE-2024-21454 has been assessed as a transient denial of service vulnerability.
2
How do I fix CVE-2024-21454?
To mitigate CVE-2024-21454, it is recommended to apply the latest security patches provided by Qualcomm for the affected firmware.
3
What software versions are affected by CVE-2024-21454?
CVE-2024-21454 affects Qualcomm C-v2x 9150, Auto 5g Modem-rf Firmware, and Auto 4g Modem Firmware versions.
4
What type of vulnerability is CVE-2024-21454 categorized as?
CVE-2024-21454 is categorized as a denial of service vulnerability affecting automotive telematics.
5
Can CVE-2024-21454 impact vehicle safety systems?
Yes, the transient denial of service caused by CVE-2024-21454 may potentially disrupt vehicle telematics systems.