CVE-2023-21669
HIGHCVSS 7.5/10EPSS 0.35%
Last modified
CVE-2023-21669 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Aqt1000 Firmware | All versions |
| Qualcomm | Wcn3991 Firmware | All versions |
| Qualcomm | Wcn3998 Firmware | All versions |
| Qualcomm | Qca6390 Firmware | All versions |
| Qualcomm | Wcn685x-5 Firmware | All versions |
| Qualcomm | Wcn685x-1 Firmware | All versions |
| Qualcomm | Flight Rb5 5g Platform Firmware | All versions |
| Qualcomm | Qca6391 Firmware | All versions |
| Qualcomm | Qca6420 Firmware | All versions |
| Qualcomm | Qca6421 Firmware | All versions |
| Qualcomm | Qca6426 Firmware | All versions |
| Qualcomm | Qca6430 Firmware | All versions |
| Qualcomm | Qca6431 Firmware | All versions |
| Qualcomm | Qca6436 Firmware | All versions |
| Qualcomm | Qcm2290 Firmware | All versions |
| Qualcomm | Qcm4290 Firmware | All versions |
| Qualcomm | Qcn9074 Firmware | All versions |
| Qualcomm | Qcs2290 Firmware | All versions |
| Qualcomm | Qcs4290 Firmware | All versions |
| Qualcomm | Qcs8250 Firmware | All versions |
| Qualcomm | Qrb5165m Firmware | All versions |
| Qualcomm | Qrb5165n Firmware | All versions |
| Qualcomm | Qrb5165 Firmware | All versions |
| Qualcomm | Sd660 Firmware | All versions |
| Qualcomm | Sd730 Firmware | All versions |
| Qualcomm | Sd855 Firmware | All versions |
| Qualcomm | Sd865 5g Firmware | All versions |
| Qualcomm | Sdm429w Firmware | All versions |
| Qualcomm | Sdx55 Firmware | All versions |
| Qualcomm | Sm6250 Firmware | All versions |
| Qualcomm | Sdm429 Firmware | All versions |
| Qualcomm | Snapdragon 675 Mobile Platform Firmware | All versions |
| Qualcomm | Sm6150-Ac Firmware | All versions |
| Qualcomm | Sm7125 Firmware | All versions |
| Qualcomm | Sm7150-Aa Firmware | All versions |
| Qualcomm | Sm7150-Ab Firmware | All versions |
| Qualcomm | Sm7150-Ac Firmware | All versions |
| Qualcomm | Sm8150 Firmware | All versions |
| Qualcomm | Sm8150-Ac Firmware | All versions |
| Qualcomm | Sm8250 Firmware | All versions |
| Qualcomm | Sm8250-Ab Firmware | All versions |
| Qualcomm | Sm8250-Ac Firmware | All versions |
| Qualcomm | Snapdragon X50 5g Modem-Rf System Firmware | All versions |
| Qualcomm | Snapdragon X55 5g Modem-Rf System Firmware | All versions |
| Qualcomm | Snapdragon Xr2 5g Platform Firmware | All versions |
| Qualcomm | Sxr2130 Firmware | All versions |
| Qualcomm | Wcd9335 Firmware | All versions |
| Qualcomm | Wcd9341 Firmware | All versions |
| Qualcomm | Wcd9370 Firmware | All versions |
| Qualcomm | Wcd9375 Firmware | All versions |
Showing 50 of 61 affected configurations. See NVD for the full list.
References
- https://www.qualcomm.com/company/product-security/bulletins/june-2023-bulletinPatch, Vendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/june-2023-bulletinPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-21669?
Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.
How severe is CVE-2023-21669?
CVE-2023-21669 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2023-21669?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-21662Memory corruption in Core Platform while printing the respon…7.8
- CVE-2023-21663Memory Corruption while accessing metadata in Display.7.8
- CVE-2023-21664Memory Corruption in Core Platform while printing the respon…7.8
- CVE-2023-21665Memory corruption in Graphics while importing a file.7.8
- CVE-2023-21666Memory Corruption in Graphics while accessing a buffer alloc…7.8
- CVE-2023-21667Transient DOS in Bluetooth HOST while passing descriptor to …6.5
- CVE-2023-21670Memory Corruption in GPU Subsystem due to arbitrary command …7.8
- CVE-2023-21671Memory Corruption in Core during syscall for Sectools Fuse c…7.8
- CVE-2023-21672Memory corruption in Audio while running concurrent tunnel p…7.8
- CVE-2023-21673Improper Access to the VM resource manager can lead to Memor…7.8
- CVE-2023-21674Windows Advanced Local Procedure Call (ALPC) Elevation of Pr…8.8
- CVE-2023-21675Windows Kernel Elevation of Privilege Vulnerability7.8
Are you affected by CVE-2023-21669?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
