WLAN Driver Memory Corruption Vulnerability
CVE-2024-43050

7.8HIGH

Key Information:

Vendor
Qualcomm
Vendor
CVE Published:
2 December 2024

Summary

The vulnerability in Qualcomm's WLAN driver arises from improper handling of IOCTL calls originating from user space. Specifically, this flaw can lead to memory corruption when attempting to issue factory test commands. This defect poses risks as it may be exploited by malicious users to manipulate system behavior, potentially gaining unauthorized access or executing arbitrary code within the system. Prompt updates are necessary for affected products to mitigate these security concerns.

Affected Version(s)

Snapdragon Snapdragon Compute AQT1000

Snapdragon Snapdragon Compute FastConnect 6200

Snapdragon Snapdragon Compute FastConnect 6700

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.