Vulnerability Description
A malformed DLC can trigger Memory Corruption in SNPE library due to out of bounds read, such as by loading an untrusted model (e.g. from a remote source).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Sd855 Firmware | - |
| Qualcomm | Sd855 | - |
| Qualcomm | Sd845 Firmware | - |
| Qualcomm | Sd845 | - |
| Qualcomm | Qcs605 Firmware | - |
| Qualcomm | Qcs605 | - |
| Qualcomm | Qcs405 Firmware | - |
| Qualcomm | Qcs405 | - |
Related Weaknesses (CWE)
References
- https://www.qualcomm.com/company/product-security/bulletins/september-2023-bulleVendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/september-2023-bulleVendor Advisory
FAQ
What is CVE-2023-28543?
CVE-2023-28543 is a vulnerability with a CVSS score of 8.1 (HIGH). A malformed DLC can trigger Memory Corruption in SNPE library due to out of bounds read, such as by loading an untrusted model (e.g. from a remote source).
How severe is CVE-2023-28543?
CVE-2023-28543 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28543?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Sd855 Firmware, Qualcomm Sd855, Qualcomm Sd845 Firmware, Qualcomm Sd845, Qualcomm Qcs605 Firmware.