CVE-2024-23366

MEDIUM

Qualcomm Qam8255p Firmware - Buffer Over-read

Title source: rule
STIX 2.1

Description

Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.

Scores

CVSS v3 6.6
EPSS 0.0007
EPSS Percentile 22.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125 CWE-126
Status published
Products (17)
qualcomm/qam8255p_firmware
qualcomm/qam8295p_firmware
qualcomm/qam8650p_firmware
qualcomm/qam8775p_firmware
qualcomm/qamsrv1h_firmware
qualcomm/qca6595_firmware
qualcomm/qca6595au_firmware
qualcomm/qca6696_firmware
qualcomm/qca6698aq_firmware
qualcomm/sa8255p_firmware
... and 7 more
Published Jan 06, 2025
Tracked Since Feb 18, 2026