CRITICAL🇵🇱 Wersja polska

CVE-2023-43538

CVSS 9.3v3.1pub. 2024-06-03upd. 2025-01-27

Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.

🤖 AI Analysis
How it works

The vulnerability stems from improper memory handling (CWE-120 — buffer overflow) during the Tunnel Invoke Manager initialization process in TZ Secure OS, which is the trusted execution environment (Trusted Zone) of Qualcomm chips. The attack vector is local, requires no privileges (PR:N) or user interaction (UI:N), and the vulnerability scope extends beyond the component where the error occurred (S:C — Scope Changed). This means an exploit could break the isolation between the trusted zone and the rest of the system.

Impact

An attacker can cause memory corruption within TZ Secure OS, which may result in unauthorized data disclosure, data modification, or complete loss of system availability, and potentially also takeover of the trusted execution environment.

Mitigation & patch

Apply patches available from the manufacturer according to references — Qualcomm security bulletin from June 2024: https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2024-bulletin.html

Who is affected

Firmware of chips: Qualcomm AQT1000, AR8035, FastConnect 6200, and other Qualcomm products listed in the manufacturer's security bulletin from June 2024.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Qualcomm Aqt1000

    HW
    Qualcomm
    all versions
  • Qualcomm Aqt1000 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Ar8035

    HW
    Qualcomm
    all versions
  • Qualcomm Ar8035 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6200

    HW
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6200 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6800

    HW
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6800 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6900

    HW
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6900 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Fastconnect 7800

    HW
    Qualcomm
    all versions
  • Qualcomm Fastconnect 7800 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qam8255p

    HW
    Qualcomm
    all versions
  • Qualcomm Qam8255p Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qam8295p

    HW
    Qualcomm
    all versions
  • Qualcomm Qam8295p Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qam8650p

    HW
    Qualcomm
    all versions
  • Qualcomm Qam8650p Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qam8775p

    HW
    Qualcomm
    all versions
  • Qualcomm Qam8775p Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qca6174a

    HW
    Qualcomm
    all versions
  • Qualcomm Qca6174a Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qca6310

    HW
    Qualcomm
    all versions
  • Qualcomm Qca6310 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qca6335

    HW
    Qualcomm
    all versions
  • Qualcomm Qca6335 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qca6391

    HW
    Qualcomm
    all versions
  • Qualcomm Qca6391 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qca6420

    HW
    Qualcomm
    all versions
  • Qualcomm Qca6420 Firmware

    OS
    Qualcomm
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-25289CRITICAL9.6PL ✓same product

Przepełnienie bufora stosu w NAN Service Discovery Frames — Qualcomm

CVE-2025-47372CRITICAL9.0PL ✓same product

Qualcomm: Memory Corruption przy ładowaniu uszkodzonego obrazu ELF

CVE-2025-27034CRITICAL9.8PL ✓same product

Qualcomm Firmware — memory corruption przy wyborze PLMN z listy SOR

CVE-2025-21483CRITICAL9.8PL ✓same product

Memory corruption w Qualcomm podczas składania pakietów RTP (NALUs)

CVE-2025-21450CRITICAL9.1PL ✓same product

Qualcomm: podatność kryptograficzna umożliwiająca Auth Bypass podczas pobierania