MEDIUM · 6.5

CVE-2024-23350

Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message...

Vulnerability Description

Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
QualcommWsa8845H Firmware-
QualcommWsa8845H-
QualcommWsa8845 Firmware-
QualcommWsa8845-
QualcommWsa8840 Firmware-
QualcommWsa8840-
QualcommWcd9395 Firmware-
QualcommWcd9395-
QualcommWcd9390 Firmware-
QualcommWcd9390-
QualcommWcd9340 Firmware-
QualcommWcd9340-
QualcommSnapdragon X75 5G Modem-Rf System Firmware-
QualcommSnapdragon X75 5G Modem-Rf System-
QualcommSnapdragon X72 5G Modem-Rf System Firmware-
QualcommSnapdragon X72 5G Modem-Rf System-
QualcommSnapdragon X35 5G Modem-Rf System Firmware-
QualcommSnapdragon X35 5G Modem-Rf System-
QualcommSnapdragon Auto 5G Modem-Rf Gen 2 Firmware-
QualcommSnapdragon Auto 5G Modem-Rf Gen 2-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-23350?

CVE-2024-23350 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message...

How severe is CVE-2024-23350?

CVE-2024-23350 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-23350?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Wsa8845H Firmware, Qualcomm Wsa8845H, Qualcomm Wsa8845 Firmware, Qualcomm Wsa8845, Qualcomm Wsa8840 Firmware.