HIGH · 8.2

CVE-2024-23359

Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.

Vulnerability Description

Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.

CVSS Score

8.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
QualcommQcn9024 Firmware-
QualcommQcn9024-
QualcommQcs4490 Firmware-
QualcommQcs4490-
QualcommQcs5430 Firmware-
QualcommQcs5430-
QualcommQcs6490 Firmware-
QualcommQcs6490-
QualcommQcs8550 Firmware-
QualcommQcs8550-
QualcommQep8111 Firmware-
QualcommQep8111-
QualcommQfw7114 Firmware-
QualcommQfw7114-
QualcommQfw7124 Firmware-
QualcommQfw7124-
QualcommQts110 Firmware-
QualcommQts110-
Qualcomm205 Mobile Platform Firmware-
Qualcomm205 Mobile Platform-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-23359?

CVE-2024-23359 is a vulnerability with a CVSS score of 8.2 (HIGH). Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.

How severe is CVE-2024-23359?

CVE-2024-23359 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-23359?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Qcn9024 Firmware, Qualcomm Qcn9024, Qualcomm Qcs4490 Firmware, Qualcomm Qcs4490, Qualcomm Qcs5430 Firmware.