CVE-2024-23358
HIGHDescription
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
Is your site exposed to CVE-2024-23358?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| qualcomm | apq8017_firmware |
| qualcomm | apq8017 |
| qualcomm | apq8037_firmware |
| qualcomm | apq8037 |
| qualcomm | ar8035_firmware |
| qualcomm | ar8035 |
| qualcomm | fastconnect_7800_firmware |
| qualcomm | fastconnect_7800 |
| qualcomm | msm8108_firmware |
| qualcomm | msm8108 |
| qualcomm | msm8209_firmware |
| qualcomm | msm8209 |
| qualcomm | msm8608_firmware |
| qualcomm | msm8608 |
| qualcomm | qca6584au_firmware |
| qualcomm | qca6584au |
| qualcomm | qca6698aq_firmware |
| qualcomm | qca6698aq |
| qualcomm | qca8081_firmware |
| qualcomm | qca8081 |
| qualcomm | qca8337_firmware |
| qualcomm | qca8337 |
| qualcomm | qcc710_firmware |
| qualcomm | qcc710 |
| qualcomm | qcn6224_firmware |
| qualcomm | qcn6224 |
| qualcomm | qcn6274_firmware |
| qualcomm | qcn6274 |
| qualcomm | qfw7114_firmware |
| qualcomm | qfw7114 |
| qualcomm | qfw7124_firmware |
| qualcomm | qfw7124 |
| qualcomm | 205_mobile_platform_firmware |
| qualcomm | 205_mobile_platform |
| qualcomm | sdm429w_firmware |
| qualcomm | sdm429w |
| qualcomm | sm8635_firmware |
| qualcomm | sm8635 |
| qualcomm | smart_audio_200_platform_firmware |
| qualcomm | smart_audio_200_platform |
| qualcomm | snapdragon_208_processor_firmware |
| qualcomm | snapdragon_208_processor |
| qualcomm | snapdragon_210_processor_firmware |
| qualcomm | snapdragon_210_processor |
| qualcomm | snapdragon_212_mobile_platform_firmware |
| qualcomm | snapdragon_212_mobile_platform |
| qualcomm | snapdragon_425_mobile_platform_firmware |
| qualcomm | snapdragon_425_mobile_platform |
| qualcomm | snapdragon_429_mobile_platform_firmware |
| qualcomm | snapdragon_429_mobile_platform |
| qualcomm | snapdragon_430_mobile_platform_firmware |
| qualcomm | snapdragon_430_mobile_platform |
| qualcomm | snapdragon_439_mobile_platform_firmware |
| qualcomm | snapdragon_439_mobile_platform |
| qualcomm | snapdragon_8_gen_3_mobile_platform_firmware |
| qualcomm | snapdragon_8_gen_3_mobile_platform |
| qualcomm | snapdragon_auto_5g_modem-rf_gen_2_firmware |
| qualcomm | snapdragon_auto_5g_modem-rf_gen_2 |
| qualcomm | snapdragon_wear_4100\+_platform_firmware |
| qualcomm | snapdragon_wear_4100\+_platform |
| qualcomm | snapdragon_x72_5g_modem-rf_system_firmware |
| qualcomm | snapdragon_x72_5g_modem-rf_system |
| qualcomm | snapdragon_x75_5g_modem-rf_system_firmware |
| qualcomm | snapdragon_x75_5g_modem-rf_system |
| qualcomm | wcd9326_firmware |
| qualcomm | wcd9326 |
| qualcomm | wcd9340_firmware |
| qualcomm | wcd9340 |
| qualcomm | wcd9370_firmware |
| qualcomm | wcd9370 |
| qualcomm | wcd9375_firmware |
| qualcomm | wcd9375 |
| qualcomm | wcd9390_firmware |
| qualcomm | wcd9390 |
| qualcomm | wcd9395_firmware |
| qualcomm | wcd9395 |
| qualcomm | wcn3610_firmware |
| qualcomm | wcn3610 |
| qualcomm | wcn3615_firmware |
| qualcomm | wcn3615 |
| qualcomm | wcn3620_firmware |
| qualcomm | wcn3620 |
| qualcomm | wcn3660b_firmware |
| qualcomm | wcn3660b |
| qualcomm | wcn3680b_firmware |
| qualcomm | wcn3680b |
| qualcomm | wcn3980_firmware |
| qualcomm | wcn3980 |
| qualcomm | wcn6755_firmware |
| qualcomm | wcn6755 |
| qualcomm | wsa8810_firmware |
| qualcomm | wsa8810 |
| qualcomm | wsa8815_firmware |
| qualcomm | wsa8815 |
| qualcomm | wsa8830_firmware |
| qualcomm | wsa8830 |
| qualcomm | wsa8832_firmware |
| qualcomm | wsa8832 |
| qualcomm | wsa8835_firmware |
| qualcomm | wsa8835 |
| qualcomm | wsa8840_firmware |
| qualcomm | wsa8840 |
| qualcomm | wsa8845_firmware |
| qualcomm | wsa8845 |
| qualcomm | wsa8845h_firmware |
| qualcomm | wsa8845h |
References
Frequently Asked Questions
What is CVE-2024-23358? +
How severe is CVE-2024-23358? +
What products are affected by CVE-2024-23358? +
How do I check if I'm vulnerable to CVE-2024-23358? +
Related Vulnerabilities
A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet …
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support …
A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and …
Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is …
The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate …
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, …