CRITICAL🇵🇱 Wersja polska

CVE-2023-33030

CVSS 9.3v3.1pub. 2024-01-02upd. 2024-11-21

Memory corruption in HLOS while running playready use-case.

🤖 AI Analysis
How it works

The vulnerability results from a buffer overflow and writing outside the boundaries of allocated memory (CWE-120, CWE-787) during PlayReady use case handling in the HLOS (High-Level Operating System) environment. Improper memory management during PlayReady data processing can lead to its corruption. A local attack vector (AV:L) means that an attacker must have local access to the device; however, no privileges (PR:N) or user interaction (UI:N) are required.

Impact

An attacker can cause memory corruption, potentially gaining full control over the system — including violations of confidentiality, integrity, and data availability. The scope of the attack extends beyond the source component (S:C), which increases the risk of privilege escalation.

Mitigation & patch

Security patches available from the manufacturer should be applied according to references — Qualcomm security bulletin from January 2024: https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin

Who is affected

Qualcomm 315 5G IoT Modem Firmware, Qualcomm 9205 LTE Modem Firmware, Qualcomm 9206 LTE Modem Firmware and related hardware products — specific versions indicated in the manufacturer's references (Qualcomm bulletin for January 2024).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Qualcomm 315 5g Iot Modem

    HW
    Qualcomm
    all versions
  • Qualcomm 315 5g Iot Modem Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm 9205 Lte Modem

    HW
    Qualcomm
    all versions
  • Qualcomm 9205 Lte Modem Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm 9206 Lte Modem

    HW
    Qualcomm
    all versions
  • Qualcomm 9206 Lte Modem Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm 9207 Lte Modem

    HW
    Qualcomm
    all versions
  • Qualcomm 9207 Lte Modem Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Apq8017

    HW
    Qualcomm
    all versions
  • Qualcomm Apq8017 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Apq8037

    HW
    Qualcomm
    all versions
  • Qualcomm Apq8037 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Apq8064au

    HW
    Qualcomm
    all versions
  • Qualcomm Apq8064au Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Aqt1000

    HW
    Qualcomm
    all versions
  • Qualcomm Aqt1000 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Ar8031

    HW
    Qualcomm
    all versions
  • Qualcomm Ar8031 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Ar8035

    HW
    Qualcomm
    all versions
  • Qualcomm Ar8035 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Csr8811

    HW
    Qualcomm
    all versions
  • Qualcomm Csr8811 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Csra6620

    HW
    Qualcomm
    all versions
  • Qualcomm Csra6620 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Csra6640

    HW
    Qualcomm
    all versions
  • Qualcomm Csra6640 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Csrb31024

    HW
    Qualcomm
    all versions
  • Qualcomm Csrb31024 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm C V2x 9150

    HW
    Qualcomm
    all versions
  • Qualcomm C V2x 9150 Firmware

    OS
    Qualcomm
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-25289CRITICAL9.6PL ✓same product

Przepełnienie bufora stosu w NAN Service Discovery Frames — Qualcomm

CVE-2025-47372CRITICAL9.0PL ✓same product

Qualcomm: Memory Corruption przy ładowaniu uszkodzonego obrazu ELF

CVE-2025-27034CRITICAL9.8PL ✓same product

Qualcomm Firmware — memory corruption przy wyborze PLMN z listy SOR

CVE-2025-21483CRITICAL9.8PL ✓same product

Memory corruption w Qualcomm podczas składania pakietów RTP (NALUs)

CVE-2025-21450CRITICAL9.1PL ✓same product

Qualcomm: podatność kryptograficzna umożliwiająca Auth Bypass podczas pobierania