CVE-2024-45547

Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryption functionality.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:qualcomm:qcc2073_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcc2073:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:qualcomm:qcc2076_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcc2076:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:qualcomm:sc8380xp_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sc8380xp:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*

History

13 Jan 2025, 21:51

Type Values Removed Values Added
CPE cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sc8380xp:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcc2073:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qcc2076_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcc2076:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qcc2073_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sc8380xp_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
Summary
  • (es) Corrupción de memoria durante el procesamiento de la llamada IOCTL invocada desde el espacio del usuario para verificar la funcionalidad de cifrado y descifrado FIPS sin extensión.
First Time Qualcomm wcd9380
Qualcomm qcc2073 Firmware
Qualcomm fastconnect 7800
Qualcomm qcc2076 Firmware
Qualcomm fastconnect 6900
Qualcomm wsa8845h Firmware
Qualcomm qcc2076
Qualcomm wsa8845h
Qualcomm wsa8845 Firmware
Qualcomm wcd9385 Firmware
Qualcomm fastconnect 6900 Firmware
Qualcomm wsa8845
Qualcomm sc8380xp
Qualcomm wsa8840
Qualcomm sc8380xp Firmware
Qualcomm wcd9380 Firmware
Qualcomm wcd9385
Qualcomm qcc2073
Qualcomm fastconnect 7800 Firmware
Qualcomm wsa8840 Firmware
Qualcomm
References () https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html - () https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html - Vendor Advisory

06 Jan 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-06 11:15

Updated : 2025-01-13 21:51


NVD link : CVE-2024-45547

Mitre link : CVE-2024-45547

CVE.ORG link : CVE-2024-45547


JSON object : View

Products Affected

qualcomm

  • wsa8840_firmware
  • sc8380xp_firmware
  • wsa8840
  • wsa8845
  • sc8380xp
  • wsa8845h_firmware
  • fastconnect_7800
  • qcc2073_firmware
  • wcd9380
  • qcc2073
  • wcd9385
  • wsa8845_firmware
  • wcd9385_firmware
  • fastconnect_7800_firmware
  • qcc2076
  • qcc2076_firmware
  • wsa8845h
  • fastconnect_6900_firmware
  • fastconnect_6900
  • wcd9380_firmware
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')