First published: Mon Jan 06 2025(Updated: )
Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Qualcomm Qam8255p Firmware | ||
Qualcomm Qam8255p | ||
All of | ||
Qualcomm Qam8295p Firmware | ||
Qualcomm Qam8295p | ||
All of | ||
Qualcomm Qam8650p Firmware | ||
Qualcomm Qam8650p | ||
All of | ||
Qualcomm Qam8775p Firmware | ||
Qualcomm Qam8775p | ||
All of | ||
Qualcomm Qamsrv1h Firmware | ||
Qualcomm Qamsrv1h | ||
All of | ||
Qualcomm Qca6595 Firmware | ||
Qualcomm Qca6595 | ||
All of | ||
Qualcomm Qca6595au Firmware | ||
Qualcomm Qca6595au | ||
All of | ||
Qualcomm Qca6696 Firmware | ||
Qualcomm Qca6696 | ||
All of | ||
Qualcomm Qca6698aq Firmware | ||
Qualcomm Qca6698aq | ||
All of | ||
Qualcomm Sa8255p Firmware | ||
Qualcomm Sa8255p | ||
All of | ||
Qualcomm Sa8295p Firmware | ||
Qualcomm Sa8295p | ||
All of | ||
Qualcomm Sa8540p Firmware | ||
Qualcomm Sa8540p | ||
All of | ||
Qualcomm Sa8650p Firmware | ||
Qualcomm Sa8650p | ||
All of | ||
Qualcomm Sa8770p Firmware | ||
Qualcomm Sa8770p | ||
All of | ||
Qualcomm Sa8775p Firmware | ||
Qualcomm Sa8775p | ||
All of | ||
Qualcomm Sa9000p Firmware | ||
Qualcomm Sa9000p | ||
All of | ||
Qualcomm Srv1h Firmware | ||
Qualcomm Srv1h |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-23366 is currently assessed as medium due to the information disclosure risk associated with mailbox write API invocations.
To fix CVE-2024-23366, users should update their Qualcomm firmware to the latest version released by the manufacturer.
The impact of CVE-2024-23366 includes the potential exposure of sensitive information when processing larger-than-allowed messages.
CVE-2024-23366 affects various Qualcomm firmware products, including Qam8255p, Qam8295p, and others listed in the vulnerability report.
CVE-2024-23366 is considered a remote vulnerability as it can be exploited through the mailbox write API from an external source.