HIGH

CVE-2023-33063

Qualcomm 315 5g Iot Modem Firmware 2023-12-05 CVSS v3.1
CVSS
7.8
KEV

Description

Memory corruption in DSP Services during a remote call from HLOS to DSP.

Summary dbcve.org

Memory corruption vulnerability in DSP (Digital Signal Processor) Services that occurs during remote procedure calls from the HLOS (High Level Operating System) to the DSP subsystem. This could allow an attacker to execute arbitrary code or cause denial of service via corrupted memory operations in the DSP context.

Mitigation

Apply vendor-provided firmware patches for affected Qualcomm Snapdragon/DSP components. Organizations should consult device manufacturers for available updates and prioritize patching mobile/embedded devices with exposed DSP interfaces.

Patch Commit

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

0.7%
Probability of exploitation in next 30 days
51.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE