First published: Mon Jan 06 2025(Updated: )
Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Qualcomm Fastconnect 6900 Firmware | ||
Qualcomm Fastconnect 6900 | ||
All of | ||
Qualcomm Fastconnect 7800 Firmware | ||
Qualcomm Fastconnect 7800 | ||
All of | ||
Qualcomm Qcc2073 Firmware | ||
Qualcomm Qcc2073 | ||
All of | ||
Qualcomm Qcc2076 Firmware | ||
Qualcomm Qcc2076 | ||
All of | ||
Qualcomm Sc8380xp Firmware | ||
Qualcomm Sc8380xp | ||
All of | ||
Qualcomm Wcd9380 Firmware | ||
Qualcomm Wcd9380 | ||
All of | ||
Qualcomm Wcd9385 Firmware | ||
Qualcomm Wcd9385 | ||
All of | ||
Qualcomm Wsa8840 Firmware | ||
Qualcomm Wsa8840 | ||
All of | ||
Qualcomm Wsa8845 Firmware | ||
Qualcomm Wsa8845 | ||
All of | ||
Qualcomm Wsa8845h Firmware | ||
Qualcomm Wsa8845h |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45546 has a high severity due to memory corruption vulnerabilities in FIPS encryption or decryption IOCTL calls.
To mitigate CVE-2024-45546, update your Qualcomm Fastconnect firmware to the latest version provided by the manufacturer.
CVE-2024-45546 affects several Qualcomm firmware products, including Fastconnect 6900, Fastconnect 7800, and Qcc2073.
CVE-2024-45546 is classified as a memory corruption vulnerability that can be exploited through user-space IOCTL calls.
Not all Qualcomm devices are vulnerable; only specific firmware versions, such as those for Fastconnect and Qcc series, are impacted.