OpenSSL serialized header verification bug causes memory corruption during keygen
CVE-2023-43531 Published on May 6, 2024

Access of Uninitialized Pointer in SPS Applications
Memory corruption while verifying the serialized header when the key pairs are generated.

NVD

Vulnerability Analysis

CVE-2023-43531 can be exploited with local system access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.

Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

Access of Uninitialized Pointer

The program accesses or uses a pointer that has not been initialized.


Products Associated with CVE-2023-43531

Want to know whenever a new CVE is published for Google Android? stack.watch will email you.

 

Affected Versions

Qualcomm, Inc. Snapdragon: qualcomm ar8035_firmware: qualcomm fastconnect_6200_firmware: qualcomm fastconnect_6700_firmware: qualcomm fastconnect_6800_firmware: qualcomm fastconnect_6900_firmware: qualcomm fastconnect_7800_firmware: qualcomm qam8255p_firmware: qualcomm qam8295p_firmware: qualcomm qam8650p_firmware: qualcomm qam8775p_firmware: qualcomm qamsrv1h_firmware: qualcomm qamsrv1m_firmware: qualcomm qca6174a_firmware: qualcomm qca6391_firmware: qualcomm qca6421_firmware: qualcomm qca6426_firmware: qualcomm qca6431_firmware: qualcomm qca6436_firmware: qualcomm qca6574_firmware: qualcomm qca6574a_firmware: qualcomm qca6574au_firmware: qualcomm qca6584au_firmware: qualcomm qca6595_firmware: qualcomm qca6595au_firmware: qualcomm qca6678aq_firmware: qualcomm qca6696_firmware: qualcomm qca6698aq_firmware: qualcomm qca6797aq_firmware: qualcomm qca8081_firmware: qualcomm qca8337_firmware: qualcomm qcc710_firmware: qualcomm qcm4490_firmware: qualcomm qcm5430_firmware: qualcomm qcm6490_firmware: qualcomm qcm8550_firmware: qualcomm qcn6224_firmware: qualcomm qcn6274_firmware: qualcomm qcs4490_firmware: qualcomm qcs5430_firmware: qualcomm qcs6490_firmware: qualcomm qcs8550_firmware: qualcomm qdu1000_firmware: qualcomm qdu1010_firmware: qualcomm qdu1110_firmware: qualcomm qdu1210_firmware: qualcomm qdx1010_firmware: qualcomm qdx1011_firmware: qualcomm qep8111_firmware: qualcomm qfw7114_firmware: qualcomm qfw7124_firmware: qualcomm qru1032_firmware: qualcomm qru1052_firmware: qualcomm qru1062_firmware: qualcomm qsm8350_firmware: qualcomm_video_collaboration_vc3_platform_firmware: qualcomm sa6145p_firmware: qualcomm sa6150p_firmware: qualcomm sa6155p_firmware: qualcomm sa7255p_firmware: qualcomm sa8145p_firmware: qualcomm sa8150p_firmware: qualcomm sa8155p_firmware: qualcomm sa8195p_firmware: qualcomm sa8255p_firmware: qualcomm sa8295p_firmware: qualcomm sa8530p_firmware: qualcomm sa8540p_firmware: qualcomm sa8620p_firmware: qualcomm sa8650p_firmware: qualcomm sa8770p_firmware: qualcomm sa8775p_firmware: qualcomm sa9000p_firmware: qualcomm sc8380xp_firmware: qualcomm sd_8_gen1_5g_firmware: qualcomm sd865_5g_firmware: qualcomm sg8275p_firmware: qualcomm sm7250p_firmware: qualcomm sm8550p_firmware: qualcomm snapdragon_4_gen_2_mobile_platform_firmware: qualcomm snapdragon_8_gen_1_mobile_platform_firmware: qualcomm snapdragon_8_gen_2_mobile_platform_firmware: qualcomm snapdragon_8_gen_3_mobile_platform_firmware: qualcomm snapdragon_865_5g_mobile_platform_firmware: qualcomm snapdragon_888_5g_mobile_platform_firmware: qualcomm snapdragon_ar2_gen_1_platform_firmware: qualcomm snapdragon_auto_5g_modem-rf_gen_2_firmware: qualcomm snapdragon_x35_5g_modem-rf_system_firmware: qualcomm snapdragon_x55_5g_modem-rf_system_firmware: qualcomm snapdragon_x65_5g_modem-rf_system_firmware: qualcomm snapdragon_x72_5g_modem-rf_system_firmware: qualcomm snapdragon_x75_5g_modem-rf_system_firmware: qualcomm snapdragon_xr2_5g_platform_firmware: qualcomm srv1h_firmware: qualcomm srv1m_firmware: qualcomm ssg2115p_firmware: qualcomm ssg2125p_firmware: qualcomm sw5100_firmware: qualcomm sw5100p_firmware: qualcomm sxr1230p_firmware: qualcomm sxr2130_firmware: qualcomm talynplus_firmware: qualcomm wcd9340_firmware: qualcomm wcd9370_firmware: qualcomm wcd9375_firmware: qualcomm wcd9380_firmware: qualcomm wcd9385_firmware: qualcomm wcd9390_firmware: qualcomm wcd9395_firmware: qualcomm wcn3950_firmware: qualcomm wcn3980_firmware: qualcomm wcn3988_firmware: qualcomm wsa8810_firmware: qualcomm wsa8815_firmware: qualcomm wsa8830_firmware: qualcomm wsa8832_firmware: qualcomm wsa8835_firmware: qualcomm wsa8840_firmware: qualcomm wsa8845_firmware: qualcomm wsa8845h_firmware:

Exploit Probability

EPSS
0.06%
Percentile
19.18%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.