CVE-2023-33071

Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:qualcomm:qca6574_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6574:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:qualcomm:qca6574a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6574a:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6574au:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:qualcomm:qca6595au_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6595au:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:qualcomm:sa6145p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa6145p:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:qualcomm:sa6150p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa6150p:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:qualcomm:sa6155_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa6155:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:qualcomm:sa6155p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa6155p:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:qualcomm:sa8145p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8145p:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:qualcomm:sa8150p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8150p:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:qualcomm:sa8155_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8155:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:qualcomm:sa8155p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8155p:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:qualcomm:sa8195p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8195p:-:*:*:*:*:*:*:*

History

12 Apr 2024, 16:15

Type Values Removed Values Added
CWE CWE-284

11 Dec 2023, 18:45

Type Values Removed Values Added
First Time Qualcomm sa8155p
Qualcomm sa8155
Qualcomm sa6155p
Qualcomm sa6155p Firmware
Qualcomm qca6574au
Qualcomm sa8145p Firmware
Qualcomm sa6150p Firmware
Qualcomm qca6574au Firmware
Qualcomm qca6574a Firmware
Qualcomm qca6574a
Qualcomm qca6574
Qualcomm qca6595au
Qualcomm sa8145p
Qualcomm sa8155p Firmware
Qualcomm sa6145p Firmware
Qualcomm sa8155 Firmware
Qualcomm sa6155
Qualcomm
Qualcomm sa8150p
Qualcomm qca6595au Firmware
Qualcomm sa6145p
Qualcomm sa6155 Firmware
Qualcomm sa8150p Firmware
Qualcomm sa8195p
Qualcomm sa6150p
Qualcomm sa8195p Firmware
Qualcomm qca6574 Firmware
CVSS v2 : unknown
v3 : 8.4
v2 : unknown
v3 : 7.8
CWE CWE-863
References () https://www.qualcomm.com/company/product-security/bulletins/december-2023-bulletin - () https://www.qualcomm.com/company/product-security/bulletins/december-2023-bulletin - Patch, Vendor Advisory
CPE cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8150p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8155:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8155p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6595au:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6574a:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8155_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8150p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa6155p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8145p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca6574_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa6155_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6574:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa6150p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa6145p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca6574au:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa6155:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa6150p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa6155p:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca6595au_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8155p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8195p:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8195p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca6574a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sa8145p:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa6145p_firmware:-:*:*:*:*:*:*:*

05 Dec 2023, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-05 03:15

Updated : 2024-04-12 16:15


NVD link : CVE-2023-33071

Mitre link : CVE-2023-33071

CVE.ORG link : CVE-2023-33071


JSON object : View

Products Affected

qualcomm

  • sa8145p
  • sa6145p
  • sa8150p
  • sa6155
  • sa6155p_firmware
  • qca6574
  • qca6595au_firmware
  • qca6574au
  • sa6155_firmware
  • sa8155p_firmware
  • sa6150p_firmware
  • qca6574a_firmware
  • qca6574a
  • sa6145p_firmware
  • sa8155
  • qca6574au_firmware
  • qca6595au
  • sa8155p
  • sa8155_firmware
  • sa8145p_firmware
  • qca6574_firmware
  • sa8195p_firmware
  • sa6150p
  • sa6155p
  • sa8195p
  • sa8150p_firmware
CWE
CWE-863

Incorrect Authorization

CWE-284

Improper Access Control