PT-2025-2513 · Qualcomm · Qualcomm Embedded Platform Microcode

Published

2024-03-13

·

Updated

2025-02-03

·

CVE-2024-38417

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions: Qualcomm embedded platform microcode (affected versions not specified)
Description: The issue is related to the hab ioctl() function in Qualcomm's microcode, which is vulnerable to a buffer overflow in memory. This can lead to the disclosure of protected information when processing IO control commands.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Over-read

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2025-01152
CVE-2024-38417

Affected Products

Qualcomm Embedded Platform Microcode