CVE-2024-21460

HIGH

Qualcomm Fastconnect 6900 Firmware - Information Disclosure

Title source: rule
STIX 2.1

Description

Information disclosure when ASLR relocates the IMEM and Secure DDR portions as one chunk in virtual address space.

Scores

CVSS v3 7.1
EPSS 0.0010
EPSS Percentile 27.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-330
Status published
Products (15)
qualcomm/fastconnect_6900_firmware
qualcomm/fastconnect_7800_firmware
qualcomm/qcm8550_firmware
qualcomm/qcs8550_firmware
qualcomm/sg8275p_firmware
qualcomm/sm8550p_firmware
qualcomm/snapdragon_8\+_gen_2_mobile_platform_firmware
qualcomm/snapdragon_8_gen_2_mobile_platform_firmware
qualcomm/wcd9380_firmware
qualcomm/wcd9385_firmware
... and 5 more
Published Jul 01, 2024
Tracked Since Feb 18, 2026