PT-2024-27996 · Qualcomm · Snapdragon+22

Published

2024-10-07

·

Updated

2024-10-16

·

CVE-2024-38425

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue concerns information disclosure when sending an implicit broadcast that contains app launch details. This implies a potential leak of sensitive information related to how applications are launched or the data associated with these launches. No specific details about affected devices, real-world incidents, or technical exploitation methods such as API endpoints, vulnerable parameters, or function names are provided.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-38425

Affected Products

Snapdragon
Fastconnect 6900 Firmware
Fastconnect 7800 Firmware
Sm7435 Firmware
Sm8635 Firmware
Sm8750 Firmware
Snapdragon 480+ 5G Mobile Platform (Sm4350-Ac) Firmware
Snapdragon 480 5G Mobile Platform Firmware
Snapdragon 4 Gen 1 Mobile Platform Firmware
Snapdragon 4 Gen 2 Mobile Platform Firmware
Snapdragon 662 Mobile Platform Firmware
Snapdragon 680 4G Mobile Platform Firmware
Snapdragon 685 4G Mobile Platform (Sm6225-Ad) Firmware
Snapdragon 695 5G Mobile Platform Firmware
Snapdragon 6 Gen 1 Mobile Platform Firmware
Snapdragon 7+ Gen 2 Mobile Platform Firmware
Snapdragon 7 Gen 1 Mobile Platform Firmware
Snapdragon 8 Gen 1 Mobile Platform Firmware
Snapdragon 8 Gen 2 Mobile Platform Firmware
Snapdragon 8 Gen 3 Mobile Platform Firmware
Wcd9380 Firmware
Wsa8830 Firmware
Wsa8835 Firmware