Cyber Posture

CVE-2024-49840

High

Published: 03 February 2025

Published
03 February 2025
Modified
05 February 2025
KEV Added
Patch
CVSS Score 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0010 27.2th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality.

Security Summary

CVE-2024-49840 is a memory corruption vulnerability that occurs while invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality. It is associated with CWE-823 (Access of Uninitialized Pointer) and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). The vulnerability affects Qualcomm products, as documented in their public security resources.

The vulnerability has a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating it requires local access with low privileges, low attack complexity, and no user interaction. A local attacker meeting these conditions can exploit the IOCTL interface to trigger memory corruption, potentially achieving high impacts on confidentiality, integrity, and availability, such as arbitrary code execution or kernel compromise.

Qualcomm has published a February 2025 security bulletin addressing this issue at https://docs.qualcomm.com/product/publicresources/securitybulletin/february-2025-bulletin.html, which security practitioners should review for details on affected components, patches, and mitigation recommendations.

Details

CWE(s)
CWE-823CWE-119

Affected Products

qualcomm
fastconnect 6900 firmware
all versions
qualcomm
fastconnect 7800 firmware
all versions
qualcomm
qcc2073 firmware
all versions
qualcomm
qcc2076 firmware
all versions
qualcomm
sc8380xp firmware
all versions
qualcomm
wcd9380 firmware
all versions
qualcomm
wcd9385 firmware
all versions
qualcomm
wsa8840 firmware
all versions
qualcomm
wsa8845 firmware
all versions
qualcomm
wsa8845h firmware
all versions

References