PT-2024-5261 · Qualcomm · Qualcomm Embedded Platform
Published
2024-01-01
·
Updated
2024-07-04
·
CVE-2024-21469
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Qualcomm embedded platform software (affected versions not specified)
Description:
The issue is related to a memory corruption problem that occurs when an invoke call and a TEE call are bound for the same trusted application. It is also associated with flaws in the access control mechanism of the TZ Secure OS microprogram component. This could potentially allow an attacker to execute arbitrary code.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qualcomm Embedded Platform