PT-2024-5261 · Qualcomm · Qualcomm Embedded Platform

Published

2024-01-01

·

Updated

2024-07-04

·

CVE-2024-21469

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Qualcomm embedded platform software (affected versions not specified)
Description: The issue is related to a memory corruption problem that occurs when an invoke call and a TEE call are bound for the same trusted application. It is also associated with flaws in the access control mechanism of the TZ Secure OS microprogram component. This could potentially allow an attacker to execute arbitrary code.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2024-05877
CVE-2024-21469

Affected Products

Qualcomm Embedded Platform