First published: Mon Jan 06 2025(Updated: )
Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Qualcomm QAM8255P | ||
Qualcomm QAM8255P Firmware | ||
All of | ||
Qualcomm QAM8295P | ||
Qualcomm QAM8295P | ||
All of | ||
Qualcomm QAM8650P Firmware | ||
Qualcomm QAM8650P Firmware | ||
All of | ||
Qualcomm QAM8775P | ||
Qualcomm QAM8775P Firmware | ||
All of | ||
Qualcomm SRV1H Firmware | ||
Qualcomm QAMSRV1H Firmware | ||
All of | ||
Qualcomm QCA6595AU Firmware | ||
Qualcomm QCA6595AU Firmware | ||
All of | ||
Qualcomm QCA6595AU Firmware | ||
Qualcomm QCA6595AU Firmware | ||
All of | ||
Qualcomm QCA6696 Firmware | ||
Qualcomm QCA6696 Firmware | ||
All of | ||
Qualcomm QCA6698AQ | ||
Qualcomm QCA6698AQ Firmware | ||
All of | ||
Qualcomm SA8255P Firmware | ||
Qualcomm SA8255P Firmware | ||
All of | ||
Qualcomm SA8295P Firmware | ||
Qualcomm SA8295P Firmware | ||
All of | ||
Qualcomm SA8540P | ||
Qualcomm SA8540P Firmware | ||
All of | ||
Qualcomm SA8650P | ||
Qualcomm SA8650P | ||
All of | ||
Qualcomm SA8770P Firmware | ||
qualcomm sa8770p firmware | ||
All of | ||
Qualcomm SA8775P | ||
Qualcomm SA8775P | ||
All of | ||
Qualcomm SA9000P Firmware | ||
Qualcomm SA9000P Firmware | ||
All of | ||
Qualcomm SRV1H | ||
Qualcomm SRV1H Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-23366 is currently assessed as medium due to the information disclosure risk associated with mailbox write API invocations.
To fix CVE-2024-23366, users should update their Qualcomm firmware to the latest version released by the manufacturer.
The impact of CVE-2024-23366 includes the potential exposure of sensitive information when processing larger-than-allowed messages.
CVE-2024-23366 affects various Qualcomm firmware products, including Qam8255p, Qam8295p, and others listed in the vulnerability report.
CVE-2024-23366 is considered a remote vulnerability as it can be exploited through the mailbox write API from an external source.