Information disclosure when ASLR relocates the IMEM and Secure DDR portions as one chunk in virtual address space.
References
Link | Resource |
---|---|
https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2024-bulletin.html | Vendor Advisory |
https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2024-bulletin.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
Configuration 15 (hide)
AND |
|
History
21 Nov 2024, 08:54
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
References | () https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2024-bulletin.html - Vendor Advisory |
02 Jul 2024, 17:56
Type | Values Removed | Values Added |
---|---|---|
First Time |
Qualcomm qcs8550 Firmware
Qualcomm snapdragon 8\+ Gen 2 Mobile Platform Qualcomm fastconnect 6900 Firmware Qualcomm qcs8550 Qualcomm snapdragon 8\+ Gen 2 Mobile Platform Firmware Qualcomm sm8550p Qualcomm wsa8840 Qualcomm wcd9395 Qualcomm fastconnect 7800 Qualcomm sm8550p Firmware Qualcomm wsa8840 Firmware Qualcomm snapdragon 8 Gen 2 Mobile Platform Qualcomm snapdragon 8 Gen 2 Mobile Platform Firmware Qualcomm qcm8550 Firmware Qualcomm qcm8550 Qualcomm wsa8845 Firmware Qualcomm wsa8845 Qualcomm Qualcomm wcd9380 Firmware Qualcomm wcd9385 Qualcomm wcd9390 Firmware Qualcomm wsa8845h Firmware Qualcomm sg8275p Firmware Qualcomm fastconnect 7800 Firmware Qualcomm wcd9385 Firmware Qualcomm wsa8845h Qualcomm fastconnect 6900 Qualcomm sg8275p Qualcomm wcd9390 Qualcomm wcd9380 Qualcomm wcd9395 Firmware |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
CPE | cpe:2.3:h:qualcomm:snapdragon_8\+_gen_2_mobile_platform:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:wcd9395_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:wcd9390_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:wcd9390:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:qcs8550:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:sg8275p:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:snapdragon_8\+_gen_2_mobile_platform_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:sm8550p:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:snapdragon_8_gen_2_mobile_platform_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:snapdragon_8_gen_2_mobile_platform:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:qcm8550:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:sg8275p_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:sm8550p_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:qcm8550_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:wcd9395:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:* cpe:2.3:o:qualcomm:qcs8550_firmware:-:*:*:*:*:*:*:* |
|
References | () https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2024-bulletin.html - Vendor Advisory | |
Summary |
|
01 Jul 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-01 15:15
Updated : 2024-11-21 08:54
NVD link : CVE-2024-21460
Mitre link : CVE-2024-21460
CVE.ORG link : CVE-2024-21460
JSON object : View
Products Affected
qualcomm
- wsa8845h_firmware
- wsa8845
- wcd9385
- sm8550p
- wsa8840_firmware
- snapdragon_8\+_gen_2_mobile_platform
- fastconnect_7800_firmware
- sg8275p_firmware
- snapdragon_8_gen_2_mobile_platform_firmware
- snapdragon_8\+_gen_2_mobile_platform_firmware
- wsa8845h
- sg8275p
- sm8550p_firmware
- fastconnect_6900_firmware
- qcm8550_firmware
- qcs8550
- wcd9395_firmware
- wcd9380_firmware
- wcd9385_firmware
- wcd9380
- fastconnect_6900
- wcd9395
- wsa8845_firmware
- wsa8840
- qcs8550_firmware
- wcd9390_firmware
- wcd9390
- snapdragon_8_gen_2_mobile_platform
- fastconnect_7800
- qcm8550
CWE
CWE-330
Use of Insufficiently Random Values