CVE-2024-45555: Integer Overflow to Buffer Overflow in Automotive OS Platform
Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45555?
CVE-2024-45555 has been classified as a high-severity vulnerability due to the potential for unauthorized program injection.
How does CVE-2024-45555 affect system security?
CVE-2024-45555 allows attackers to bypass boot verification, enabling them to boot tampered IFS2 system images.
What systems are affected by CVE-2024-45555?
CVE-2024-45555 affects various Qualcomm firmware versions including MSM8996AU, QAM8255P, QAM8295P, and several others.
How do I fix CVE-2024-45555?
Addressing CVE-2024-45555 requires updating the affected Qualcomm firmware to the latest security release that addresses this vulnerability.
Can CVE-2024-45555 lead to data breaches?
Yes, CVE-2024-45555 could potentially lead to data breaches by allowing the execution of unauthorized code on vulnerable devices.