#VU80383 Improper Authorization in Qualcomm products


Vulnerability identifier: #VU80383

Vulnerability risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-33019

CWE-ID: CWE-285

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
9206 LTE Modem
Mobile applications / Mobile firmware & hardware
APQ8052
Mobile applications / Mobile firmware & hardware
APQ8056
Mobile applications / Mobile firmware & hardware
APQ8076
Mobile applications / Mobile firmware & hardware
AR8031
Mobile applications / Mobile firmware & hardware
C-V2X 9150
Mobile applications / Mobile firmware & hardware
CSRA6620
Mobile applications / Mobile firmware & hardware
CSRA6640
Mobile applications / Mobile firmware & hardware
FastConnect 6200
Mobile applications / Mobile firmware & hardware
Home Hub 100 Platform
Mobile applications / Mobile firmware & hardware
MDM9250
Mobile applications / Mobile firmware & hardware
MDM9628
Mobile applications / Mobile firmware & hardware
MSM8108
Mobile applications / Mobile firmware & hardware
MSM8209
Mobile applications / Mobile firmware & hardware
MSM8608
Mobile applications / Mobile firmware & hardware
QCA6175A
Mobile applications / Mobile firmware & hardware
QCA6554A
Mobile applications / Mobile firmware & hardware
QCA6564A
Mobile applications / Mobile firmware & hardware
QCA6564AU
Mobile applications / Mobile firmware & hardware
QCA6574
Mobile applications / Mobile firmware & hardware
QCA6574A
Mobile applications / Mobile firmware & hardware
QCA6584
Mobile applications / Mobile firmware & hardware
QCA6584AU
Mobile applications / Mobile firmware & hardware
QCA6595
Mobile applications / Mobile firmware & hardware
QCA6595AU
Mobile applications / Mobile firmware & hardware
QCA6696
Mobile applications / Mobile firmware & hardware
QCA9367
Mobile applications / Mobile firmware & hardware
Qualcomm 205 Mobile Platform
Mobile applications / Mobile firmware & hardware
Qualcomm 215 Mobile Platform
Mobile applications / Mobile firmware & hardware
SD626
Mobile applications / Mobile firmware & hardware
SDX20M
Mobile applications / Mobile firmware & hardware
Smart Audio 200 Platform
Mobile applications / Mobile firmware & hardware
Smart Audio 400 Platform
Mobile applications / Mobile firmware & hardware
Smart Display 200 Platform (APQ5053-AA)
Mobile applications / Mobile firmware & hardware
Snapdragon 1200 Wearable Platform
Mobile applications / Mobile firmware & hardware
Snapdragon 208 Processor
Mobile applications / Mobile firmware & hardware
Snapdragon 210 Processor
Mobile applications / Mobile firmware & hardware
Snapdragon 212 Mobile Platform
Mobile applications / Mobile firmware & hardware
Snapdragon 425 Mobile Platform
Mobile applications / Mobile firmware & hardware
Snapdragon 429 Mobile Platform
Mobile applications / Mobile firmware & hardware
Snapdragon 439 Mobile Platform
Mobile applications / Mobile firmware & hardware
Snapdragon 450 Mobile Platform
Mobile applications / Mobile firmware & hardware
Snapdragon 617 Processor
Mobile applications / Mobile firmware & hardware
Snapdragon 625 Mobile Platform
Mobile applications / Mobile firmware & hardware
Snapdragon 626 Mobile Platform
Mobile applications / Mobile firmware & hardware
Snapdragon 632 Mobile Platform
Mobile applications / Mobile firmware & hardware
Snapdragon 650 Mobile Platform
Mobile applications / Mobile firmware & hardware
Snapdragon 652 Mobile Platform
Mobile applications / Mobile firmware & hardware
Snapdragon 653 Mobile Platform
Mobile applications / Mobile firmware & hardware
Snapdragon 820 Automotive Platform
Mobile applications / Mobile firmware & hardware
Snapdragon Auto 5G Modem-RF
Mobile applications / Mobile firmware & hardware
Snapdragon Wear 2100 Platform
Mobile applications / Mobile firmware & hardware
Snapdragon Wear 2500 Platform
Mobile applications / Mobile firmware & hardware
Snapdragon Wear 3100 Platform
Mobile applications / Mobile firmware & hardware
Snapdragon Wear 4100+ Platform
Mobile applications / Mobile firmware & hardware
Snapdragon X12 LTE Modem
Mobile applications / Mobile firmware & hardware
Snapdragon X20 LTE Modem
Mobile applications / Mobile firmware & hardware
Snapdragon X5 LTE Modem
Mobile applications / Mobile firmware & hardware
Vision Intelligence 100 Platform (APQ8053-AA)
Mobile applications / Mobile firmware & hardware
Vision Intelligence 200 Platform (APQ8053-AC)
Mobile applications / Mobile firmware & hardware
WCD9326
Mobile applications / Mobile firmware & hardware
WCD9330
Mobile applications / Mobile firmware & hardware
WCD9335
Mobile applications / Mobile firmware & hardware
WCN3610
Mobile applications / Mobile firmware & hardware
WCN3615
Mobile applications / Mobile firmware & hardware
WCN3620
Mobile applications / Mobile firmware & hardware
WCN3660
Mobile applications / Mobile firmware & hardware
WCN3660B
Mobile applications / Mobile firmware & hardware
WCN3680
Mobile applications / Mobile firmware & hardware
WCN3680B
Mobile applications / Mobile firmware & hardware
WCN3980
Mobile applications / Mobile firmware & hardware
WSA8810
Mobile applications / Mobile firmware & hardware
WSA8815
Mobile applications / Mobile firmware & hardware
APQ8017
Hardware solutions / Firmware
MDM9650
Hardware solutions / Firmware
MSM8909W
Hardware solutions / Firmware
MSM8996AU
Hardware solutions / Firmware
QCA6174A
Hardware solutions / Firmware
QCA6574AU
Hardware solutions / Firmware
QCA9377
Hardware solutions / Firmware
QCA9379
Hardware solutions / Firmware
SDM429W
Hardware solutions / Firmware

Vendor: Qualcomm

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation in WLAN Host. A remote attacker can perform a denial of service (DoS) attack.

Mitigation
Install security update from vendor's website.

Vulnerable software versions

9206 LTE Modem: All versions

APQ8017: All versions

APQ8052: All versions

APQ8056: All versions

APQ8076: All versions

AR8031: All versions

C-V2X 9150: All versions

CSRA6620: All versions

CSRA6640: All versions

FastConnect 6200: All versions

Home Hub 100 Platform: All versions

MDM9250: All versions

MDM9628: All versions

MDM9650: All versions

MSM8108: All versions

MSM8209: All versions

MSM8608: All versions

MSM8909W: All versions

MSM8996AU: All versions

QCA6174A: All versions

QCA6175A: All versions

QCA6554A: All versions

QCA6564A: All versions

QCA6564AU: All versions

QCA6574: All versions

QCA6574A: All versions

QCA6574AU: All versions

QCA6584: All versions

QCA6584AU: All versions

QCA6595: All versions

QCA6595AU: All versions

QCA6696: All versions

QCA9367: All versions

QCA9377: All versions

QCA9379: All versions

Qualcomm 205 Mobile Platform: All versions

Qualcomm 215 Mobile Platform: All versions

SD626: All versions

SDM429W: All versions

SDX20M: All versions

Smart Audio 200 Platform: All versions

Smart Audio 400 Platform: All versions

Smart Display 200 Platform (APQ5053-AA): All versions

Snapdragon 1200 Wearable Platform: All versions

Snapdragon 208 Processor: All versions

Snapdragon 210 Processor: All versions

Snapdragon 212 Mobile Platform: All versions

Snapdragon 425 Mobile Platform: All versions

Snapdragon 429 Mobile Platform: All versions

Snapdragon 439 Mobile Platform: All versions

Snapdragon 450 Mobile Platform: All versions

Snapdragon 617 Processor: All versions

Snapdragon 625 Mobile Platform: All versions

Snapdragon 626 Mobile Platform: All versions

Snapdragon 632 Mobile Platform: All versions

Snapdragon 650 Mobile Platform: All versions

Snapdragon 652 Mobile Platform: All versions

Snapdragon 653 Mobile Platform: All versions

Snapdragon 820 Automotive Platform: All versions

Snapdragon Auto 5G Modem-RF: All versions

Snapdragon Wear 2100 Platform: All versions

Snapdragon Wear 2500 Platform: All versions

Snapdragon Wear 3100 Platform: All versions

Snapdragon Wear 4100+ Platform: All versions

Snapdragon X12 LTE Modem: All versions

Snapdragon X20 LTE Modem: All versions

Snapdragon X5 LTE Modem: All versions

Vision Intelligence 100 Platform (APQ8053-AA): All versions

Vision Intelligence 200 Platform (APQ8053-AC): All versions

WCD9326: All versions

WCD9330: All versions

WCD9335: All versions

WCN3610: All versions

WCN3615: All versions

WCN3620: All versions

WCN3660: All versions

WCN3660B: All versions

WCN3680: All versions

WCN3680B: All versions

WCN3980: All versions

WSA8810: All versions

WSA8815: All versions


External links
http://docs.qualcomm.com/product/publicresources/securitybulletin/september-2023-bulletin.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability