CVE-2024-38425
6.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Exploitability: 1.8 / Impact: 4.2
Source: product-security@qualcomm.com (Secondary)
Description
Information disclosure while sending implicit broadcast containing APP launch information.
Affected (24)
Products: Qualcomm: Wsa8835 Firmware, Wsa8830 Firmware, Wcd9380 Firmware, Snapdragon 8 Gen 2 Mobile Platform Firmware, Snapdragon 8 Gen 1 Mobile Platform Firmware, Snapdragon 8 Gen 3 Mobile Platform Firmware, Snapdragon 7+ Gen 2 Mobile Platform Firmware, Snapdragon 7 Gen 1 Mobile Platform Firmware, Snapdragon 695 5g Mobile Platform Firmware, Snapdragon 685 4g Mobile Platform (sm6225 Ad) Firmware, Snapdragon 680 4g Mobile Platform Firmware, Snapdragon 662 Mobile Platform Firmware, Snapdragon 6 Gen 1 Mobile Platform Firmware, Snapdragon 480+ 5g Mobile Platform (sm4350 Ac) Firmware, Snapdragon 480 5g Mobile Platform Firmware, Snapdragon 4 Gen 2 Mobile Platform Firmware, Snapdragon 4 Gen 1 Mobile Platform Firmware, Sm8750 Firmware, Sm8635 Firmware, Sm7435 Firmware, Fastconnect 7800 Firmware, Fastconnect 6900 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Wsa8835 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Wsa8830 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Wcd9380 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 8+ Gen 2 Mobile Platform | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 8+ Gen 1 Mobile Platform | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 8 Gen 3 Mobile Platform | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 8 Gen 2 Mobile Platform | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 8 Gen 1 Mobile Platform | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 7+ Gen 2 Mobile Platform | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 7 Gen 1 Mobile Platform | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 695 5g Mobile Platform | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 685 4g Mobile Platform (sm6225 Ad) | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 680 4g Mobile Platform | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 662 Mobile Platform | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 6 Gen 1 Mobile Platform | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 480+ 5g Mobile Platform (sm4350 Ac) | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 480 5g Mobile Platform | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 4 Gen 2 Mobile Platform | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Snapdragon 4 Gen 1 Mobile Platform | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Sm8750 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Sm8635 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Sm7435 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Fastconnect 7800 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Qualcomm Fastconnect 6900 | All versions |
Related CWEs
CWE-285
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-863
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
References (1)
Source: product-security@qualcomm.com
Vendor Advisory
Timeline
No history available yet.