CVE-2023-33092
HIGHCVSS 7.8/10EPSS 0.16%
Last modified
CVE-2023-33092 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Aqt1000 Firmware | All versions |
| Qualcomm | Fastconnect 6200 Firmware | All versions |
| Qualcomm | Fastconnect 6700 Firmware | All versions |
| Qualcomm | Fastconnect 6800 Firmware | All versions |
| Qualcomm | Fastconnect 6900 Firmware | All versions |
| Qualcomm | Fastconnect 7800 Firmware | All versions |
| Qualcomm | Qca6310 Firmware | All versions |
| Qualcomm | Qca6320 Firmware | All versions |
| Qualcomm | Qca6391 Firmware | All versions |
| Qualcomm | Qca6420 Firmware | All versions |
| Qualcomm | Qca6430 Firmware | All versions |
| Qualcomm | Qcm4325 Firmware | All versions |
| Qualcomm | Qcm4490 Firmware | All versions |
| Qualcomm | Qcm5430 Firmware | All versions |
| Qualcomm | Qcm6490 Firmware | All versions |
| Qualcomm | Qcm8550 Firmware | All versions |
| Qualcomm | Qcs4490 Firmware | All versions |
| Qualcomm | Qcs5430 Firmware | All versions |
| Qualcomm | Qcs6490 Firmware | All versions |
| Qualcomm | Qcs7230 Firmware | All versions |
| Qualcomm | Qcs8250 Firmware | All versions |
| Qualcomm | Qcs8550 Firmware | All versions |
| Qualcomm | Qualcomm 215 Mobile Platform Firmware | All versions |
| Qualcomm | Video Collaboration Vc3 Platform Firmware | All versions |
| Qualcomm | Video Collaboration Vc5 Platform Firmware | All versions |
| Qualcomm | Sd730 Firmware | All versions |
| Qualcomm | Sd835 Firmware | All versions |
| Qualcomm | Sd855 Firmware | All versions |
| Qualcomm | Sd888 Firmware | All versions |
| Qualcomm | Sg4150p Firmware | All versions |
| Qualcomm | Sm6250 Firmware | All versions |
| Qualcomm | Sm7250p Firmware | All versions |
| Qualcomm | Sm7315 Firmware | All versions |
| Qualcomm | Sm7325p Firmware | All versions |
| Qualcomm | Sm8550p Firmware | All versions |
| Qualcomm | Snapdragon 4 Gen 1 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 4 Gen 2 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 460 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 480 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 480\+ 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 662 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 680 4g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 685 4g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 690 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 695 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 720g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 730 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 730g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 732g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 765 5g Mobile Platform Firmware | All versions |
Showing 50 of 95 affected configurations. See NVD for the full list.
References
- https://www.qualcomm.com/company/product-security/bulletins/december-2023-bulletinPatch, Vendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/december-2023-bulletinPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-33092?
Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size.
How severe is CVE-2023-33092?
CVE-2023-33092 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.16% probability of exploitation in the next 30 days.
How do I fix CVE-2023-33092?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2023-33092?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
