Cyber Posture

CVE-2024-49834

High

Published: 03 February 2025

Published
03 February 2025
Modified
05 February 2025
KEV Added
Patch
CVSS Score 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0011 29.3th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

Memory corruption while power-up or power-down sequence of the camera sensor.

Security Summary

CVE-2024-49834 is a memory corruption vulnerability (CWE-129) occurring during the power-up or power-down sequence of the camera sensor in Qualcomm products. It has a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to its potential for significant impact on confidentiality, integrity, and availability. The issue affects components within Qualcomm chipsets or devices that handle camera sensor operations.

A local attacker with low privileges can exploit this vulnerability without user interaction by triggering the faulty power sequence, leading to memory corruption. Successful exploitation could allow the attacker to gain high-level control over the affected system, potentially executing arbitrary code, escalating privileges, or causing denial of service through crashes or data corruption.

Qualcomm's February 2025 security bulletin provides details on affected products and recommends applying the latest firmware or software patches to mitigate the vulnerability, as outlined at https://docs.qualcomm.com/product/publicresources/securitybulletin/february-2025-bulletin.html. Security practitioners should verify device applicability and prioritize updates for systems with exposed camera sensors.

Details

CWE(s)
CWE-129

Affected Products

qualcomm
csra6620 firmware
all versions
qualcomm
csra6640 firmware
all versions
qualcomm
fastconnect 6200 firmware
all versions
qualcomm
fastconnect 6700 firmware
all versions
qualcomm
fastconnect 6900 firmware
all versions
qualcomm
fastconnect 7800 firmware
all versions
qualcomm
flight rb5 5g platform firmware
all versions
qualcomm
qam8255p firmware
all versions
qualcomm
qam8650p firmware
all versions
qualcomm
qam8775p firmware
all versions
+117 more product configuration(s) — see NVD for full list

References