Loading HuntDB...

CVE-2023-28554

MEDIUM
Published 2023-11-07T05:26:35.362Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2023-28554. We'll provide specific mitigation strategies based on your environment and risk profile.

CVSS Score

V3.1
6.1
/10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Base Score Metrics
Exploitability: N/A Impact: N/A

EPSS Score

v2025.03.14
0.001
probability
of exploitation in the wild

There is a 0.1% chance that this vulnerability will be exploited in the wild within the next 30 days.

Updated: 2025-06-25
Exploit Probability
Percentile: 0.176
Higher than 17.6% of all CVEs

Attack Vector Metrics

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED

Impact Metrics

Confidentiality
HIGH
Integrity
NONE
Availability
LOW

Description

Information Disclosure in Qualcomm IPC while reading values from shared memory in VM.

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

Affected Products

Affected Versions:

AQT1000 AR9380 C-V2X 9150 CSR8811 FastConnect 6200 FastConnect 6800 FastConnect 6900 FastConnect 7800 Immersive Home 214 Platform Immersive Home 216 Platform Immersive Home 316 Platform Immersive Home 318 Platform IPQ4019 IPQ4028 IPQ4029 IPQ5010 IPQ5028 IPQ6010 IPQ6018 IPQ6028 IPQ8064 IPQ8065 IPQ8068 IPQ8070A IPQ8071A IPQ8072A IPQ8074A IPQ8076 IPQ8076A IPQ8078 IPQ8078A IPQ8173 IPQ8174 PMP8074 QAM8255P QAM8295P QCA4024 QCA6310 QCA6320 QCA6391 QCA6420 QCA6426 QCA6430 QCA6436 QCA6554A QCA6564AU QCA6574 QCA6574A QCA6574AU QCA6584AU QCA6595 QCA6595AU QCA6696 QCA6698AQ QCA6797AQ QCA7500 QCA8072 QCA8075 QCA8081 QCA8337 QCA9880 QCA9886 QCA9888 QCA9889 QCA9898 QCA9980 QCA9984 QCA9985 QCA9990 QCA9992 QCA9994 QCN5021 QCN5022 QCN5024 QCN5052 QCN5054 QCN5122 QCN5124 QCN5152 QCN5154 QCN5164 QCN6023 QCN6024 QCN6122 QCN6132 QCN9000 QCN9022 QCN9024 QCN9070 QCN9072 QCN9074 QCN9100 QCS410 QCS610 QCS8155 QSM8250 Qualcomm 205 Mobile Platform Qualcomm 215 Mobile Platform Qualcomm Video Collaboration VC1 Platform Qualcomm Video Collaboration VC3 Platform SA6145P SA6150P SA6155P SA8145P SA8150P SA8155P SA8195P SA8255P SA8295P SD835 SD855 SD865 5G SDX55 Snapdragon 210 Processor Snapdragon 212 Mobile Platform Snapdragon 8 Gen 1 Mobile Platform Snapdragon 835 Mobile PC Platform Snapdragon 855 Mobile Platform Snapdragon 855+/860 Mobile Platform (SM8150-AC) Snapdragon 865 5G Mobile Platform Snapdragon 865+ 5G Mobile Platform (SM8250-AB) Snapdragon 870 5G Mobile Platform (SM8250-AC) Snapdragon 888 5G Mobile Platform Snapdragon 888+ 5G Mobile Platform (SM8350-AC) Snapdragon W5+ Gen 1 Wearable Platform Snapdragon Wear 4100+ Platform Snapdragon X55 5G Modem-RF System Snapdragon XR2 5G Platform SW5100 SW5100P SXR2130 WCD9335 WCD9340 WCD9341 WCD9370 WCD9380 WCD9385 WCN3610 WCN3660B WCN3680B WCN3950 WCN3980 WCN3988 WCN3990 WSA8810 WSA8815 WSA8830 WSA8835

EU Vulnerability Database

Monitored by ENISA for EU cybersecurity

EU Coordination

Not EU Coordinated

Exploitation Status

No Known Exploitation

ENISA Analysis

Malicious code in bioql (PyPI)

Affected Products (ENISA)

qualcomm, inc.
snapdragon

ENISA Scoring

CVSS Score (3.1)

6.1
/10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

EPSS Score

0.060
probability

Data provided by ENISA EU Vulnerability Database. Last updated: October 3, 2025

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed MODERATE

GHSA-gc7p-mvx7-rv54

Advisory Details

Information Disclosure in Qualcomm IPC while reading values from shared memory in VM.

CVSS Scoring

CVSS Score

5.0

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Advisory provided by GitHub Security Advisory Database. Published: November 14, 2023, Modified: November 14, 2023

References

Published: 2023-11-07T05:26:35.362Z
Last Modified: 2024-08-02T13:43:23.243Z
Copied to clipboard!