CVE-2023-33046
HIGHDescription
Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.
Is your site exposed to CVE-2023-33046?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| qualcomm | ar8035_firmware |
| qualcomm | ar8035 |
| qualcomm | fastconnect_6900_firmware |
| qualcomm | fastconnect_6900 |
| qualcomm | fastconnect_7800_firmware |
| qualcomm | fastconnect_7800 |
| qualcomm | flight_rb5_5g_platform_firmware |
| qualcomm | flight_rb5_5g_platform |
| qualcomm | qam8295p_firmware |
| qualcomm | qam8295p |
| qualcomm | qca6391_firmware |
| qualcomm | qca6391 |
| qualcomm | qca6574au_firmware |
| qualcomm | qca6574au |
| qualcomm | qca6595_firmware |
| qualcomm | qca6595 |
| qualcomm | qca6696_firmware |
| qualcomm | qca6696 |
| qualcomm | qca6698aq_firmware |
| qualcomm | qca6698aq |
| qualcomm | qca8081_firmware |
| qualcomm | qca8081 |
| qualcomm | qca8337_firmware |
| qualcomm | qca8337 |
| qualcomm | qcm8550_firmware |
| qualcomm | qcm8550 |
| qualcomm | qcn6024_firmware |
| qualcomm | qcn6024 |
| qualcomm | qcn9011_firmware |
| qualcomm | qcn9011 |
| qualcomm | qcn9012_firmware |
| qualcomm | qcn9012 |
| qualcomm | qcn9024_firmware |
| qualcomm | qcn9024 |
| qualcomm | qcs7230_firmware |
| qualcomm | qcs7230 |
| qualcomm | qcs8250_firmware |
| qualcomm | qcs8250 |
| qualcomm | qcs8550_firmware |
| qualcomm | qcs8550 |
| qualcomm | qrb5165m_firmware |
| qualcomm | qrb5165m |
| qualcomm | qrb5165n_firmware |
| qualcomm | qrb5165n |
| qualcomm | video_collaboration_vc5_platform_firmware |
| qualcomm | video_collaboration_vc5_platform |
| qualcomm | robotics_rb5_platform_firmware |
| qualcomm | robotics_rb5_platform |
| qualcomm | sa8295p_firmware |
| qualcomm | sa8295p |
| qualcomm | sa8540p_firmware |
| qualcomm | sa8540p |
| qualcomm | sa9000p_firmware |
| qualcomm | sa9000p |
| qualcomm | sg8275p_firmware |
| qualcomm | sg8275p |
| qualcomm | sm8550p_firmware |
| qualcomm | sm8550p |
| qualcomm | snapdragon_8_gen_2_mobile_platform_firmware |
| qualcomm | snapdragon_8_gen_2_mobile_platform |
| qualcomm | snapdragon_8\+_gen_2_mobile_platform_firmware |
| qualcomm | snapdragon_8\+_gen_2_mobile_platform |
| qualcomm | snapdragon_8cx_gen_3_compute_platform_firmware |
| qualcomm | snapdragon_8cx_gen_3_compute_platform |
| qualcomm | snapdragon_ar2_gen_1_platform_firmware |
| qualcomm | snapdragon_ar2_gen_1_platform |
| qualcomm | snapdragon_x65_5g_modem-rf_system_firmware |
| qualcomm | snapdragon_x65_5g_modem-rf_system |
| qualcomm | snapdragon_x70_modem-rf_system_firmware |
| qualcomm | snapdragon_x70_modem-rf_system |
| qualcomm | ssg2115p_firmware |
| qualcomm | ssg2115p |
| qualcomm | ssg2125p_firmware |
| qualcomm | ssg2125p |
| qualcomm | sxr1230p_firmware |
| qualcomm | sxr1230p |
| qualcomm | sxr2230p_firmware |
| qualcomm | sxr2230p |
| qualcomm | wcd9380_firmware |
| qualcomm | wcd9380 |
| qualcomm | wcd9385_firmware |
| qualcomm | wcd9385 |
| qualcomm | wcd9390_firmware |
| qualcomm | wcd9390 |
| qualcomm | wcd9395_firmware |
| qualcomm | wcd9395 |
| qualcomm | wsa8830_firmware |
| qualcomm | wsa8830 |
| qualcomm | wsa8832_firmware |
| qualcomm | wsa8832 |
| qualcomm | wsa8835_firmware |
| qualcomm | wsa8835 |
| qualcomm | wsa8840_firmware |
| qualcomm | wsa8840 |
| qualcomm | wsa8845_firmware |
| qualcomm | wsa8845 |
| qualcomm | wsa8845h_firmware |
| qualcomm | wsa8845h |
References
Frequently Asked Questions
What is CVE-2023-33046? +
How severe is CVE-2023-33046? +
What products are affected by CVE-2023-33046? +
How do I check if I'm vulnerable to CVE-2023-33046? +
Related Vulnerabilities
When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations …
MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) …
Duende.AccessTokenManagement is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. Duende.AccessTokenManagement contains a race condition …
A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could …
conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. In versions prior to 2025.4.10, a race …
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at …