CRITICAL🇵🇱 Wersja polska

CVE-2023-33072

CVSS 9.3v3.1pub. 2024-02-06upd. 2025-08-11

Memory corruption in Core while processing control functions.

🤖 AI Analysis
How it works

The vulnerability results from improper handling of memory buffers (classic buffer overflow) in the Core component during execution of control functions. A local attacker, without needing elevated privileges or user interaction, can deliver specially crafted data that leads to memory corruption. The scope of the breach extends beyond the context of the attacked component (Scope: Changed), indicating the possibility of affecting isolated system resources.

Impact

Successful exploitation of this vulnerability may allow an attacker to gain full control over the affected system — including confidentiality, integrity, and availability of data — with potential privilege escalation beyond the boundaries of the original component.

Mitigation & patch

Apply patches available from the manufacturer according to references — Qualcomm security bulletin from February 2024 (https://www.qualcomm.com/company/product-security/bulletins/february-2024-bulletin). OEM device manufacturers should implement firmware updates immediately after they become available.

Who is affected

Firmware of Qualcomm chipsets: 315 5G IoT Modem, 9205 LTE Modem, AQT1000, and other Qualcomm products listed in the Qualcomm security bulletin from February 2024.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Qualcomm 315 5g Iot Modem

    HW
    Qualcomm
    all versions
  • Qualcomm 315 5g Iot Modem Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm 9205 Lte Modem

    HW
    Qualcomm
    all versions
  • Qualcomm 9205 Lte Modem Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Aqt1000

    HW
    Qualcomm
    all versions
  • Qualcomm Aqt1000 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Ar8031

    HW
    Qualcomm
    all versions
  • Qualcomm Ar8031 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Ar8035

    HW
    Qualcomm
    all versions
  • Qualcomm Ar8035 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Csra6620

    HW
    Qualcomm
    all versions
  • Qualcomm Csra6620 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Csra6640

    HW
    Qualcomm
    all versions
  • Qualcomm Csra6640 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Csrb31024

    HW
    Qualcomm
    all versions
  • Qualcomm Csrb31024 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6200

    HW
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6200 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6700

    HW
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6700 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6800

    HW
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6800 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6900

    HW
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6900 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Fastconnect 7800

    HW
    Qualcomm
    all versions
  • Qualcomm Fastconnect 7800 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Flight Rb5 5g Platform

    HW
    Qualcomm
    all versions
  • Qualcomm Flight Rb5 5g Platform Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Immersive Home 3210 Platform

    HW
    Qualcomm
    all versions
  • Qualcomm Immersive Home 3210 Platform Firmware

    OS
    Qualcomm
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-25289CRITICAL9.6PL ✓same product

Przepełnienie bufora stosu w NAN Service Discovery Frames — Qualcomm

CVE-2025-47372CRITICAL9.0PL ✓same product

Qualcomm: Memory Corruption przy ładowaniu uszkodzonego obrazu ELF

CVE-2025-21483CRITICAL9.8PL ✓same product

Memory corruption w Qualcomm podczas składania pakietów RTP (NALUs)

CVE-2025-27034CRITICAL9.8PL ✓same product

Qualcomm Firmware — memory corruption przy wyborze PLMN z listy SOR

CVE-2025-21450CRITICAL9.1PL ✓same product

Qualcomm: podatność kryptograficzna umożliwiająca Auth Bypass podczas pobierania