CVE detail
CVE-2023-28540
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 11.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
2 source links · newest first
- Qualcomm patches 3 actively exploited zero-daysHelp Net Security
Qualcomm has fixed three actively exploited vulnerabilities (CVE-2023-33106, CVE-2023-33107, CVE-2023-33063) in its Adreno GPU and Compute DSP drivers. Vulnerabilities exploited in Qualcomm GPU and DSP drivers The US-based semiconductor company has been notified by Google Threat Analysis Group and Google Project Zero that CVE-2023-33106, CVE-2023-33107, CVE-2023-33063, and CVE-2022-22071 “may be under limited, targeted exploitation”. CVE-2022-22071 is an older use-after-free vulnerability found in Automotive Android OS and patched in May 2022. Additional information about the three … More →
newswww.helpnetsecurity.comOct 4, 2023, 1:43 PM - Chipmaker Qualcomm warns of three actively exploited zero-daysSecurity Affairs
Chipmaker Qualcomm addressed 17 vulnerabilities in various components and warns of three other actively exploited zero-day flaws. Chipmaker Qualcomm released security updates to address 17 vulnerabilities in several components. Three out of 17 flaws are rated Critical, 13 are rated High, and one is rated Medium in severity. The company is also warning that three […]
newssecurityaffairs.comOct 4, 2023, 1:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-33022CVSS 8.4 · High
Memory corruption in HLOS while invoking IOCTL calls from user-space.
- CVE-2023-33054CVSS 9.1 · Critical
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
- CVE-2023-33079CVSS 7.8 · High
Memory corruption in Audio while running invalid audio recording from ADSP.
- CVE-2023-33055CVSS 7.8 · High
Memory Corruption in Audio while invoking callback function in driver from ADSP.
- CVE-2023-33035CVSS 7.8 · High
Memory corruption while invoking callback function of AFE from ADSP.
- CVE-2023-21670CVSS 7.8 · High
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.