CVE-2023-43529
π TL;DR
This vulnerability allows attackers to cause a denial-of-service condition in IKEv2 implementations by sending malformed fragment packets. It affects systems using Qualcomm's IKEv2 implementation, potentially disrupting VPN and secure communication services.
π» Affected Systems
- Qualcomm IKEv2 implementation
π¦ What is this software?
Snapdragon 4 Gen 1 Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 4 Gen 1 Mobile Firmware β
Snapdragon 460 Mobile Firmware by Qualcomm
Snapdragon 480 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 480 5g Mobile Firmware β
Snapdragon 480 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 480 5g Mobile Firmware β
Snapdragon 662 Mobile Firmware by Qualcomm
Snapdragon 665 Mobile Firmware by Qualcomm
Snapdragon 675 Mobile Firmware by Qualcomm
Snapdragon 678 Mobile Firmware by Qualcomm
Snapdragon 680 4g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 680 4g Mobile Firmware β
Snapdragon 685 4g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 685 4g Mobile Firmware β
Snapdragon 690 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 690 5g Mobile Firmware β
Snapdragon 695 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 695 5g Mobile Firmware β
Snapdragon 720g Mobile Firmware by Qualcomm
Snapdragon 730 Mobile Firmware by Qualcomm
Snapdragon 730g Mobile Firmware by Qualcomm
Snapdragon 732g Mobile Firmware by Qualcomm
Snapdragon 750g 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 750g 5g Mobile Firmware β
Snapdragon 765 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 765 5g Mobile Firmware β
Snapdragon 765g 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 765g 5g Mobile Firmware β
Snapdragon 768g 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 768g 5g Mobile Firmware β
Snapdragon 778g 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 778g 5g Mobile Firmware β
Snapdragon 778g 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 778g 5g Mobile Firmware β
Snapdragon 780g 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 780g 5g Mobile Firmware β
Snapdragon 782g Mobile Firmware by Qualcomm
Snapdragon 7c Compute Firmware by Qualcomm
Snapdragon 7c Gen 2 Compute Firmware by Qualcomm
View all CVEs affecting Snapdragon 7c Gen 2 Compute Firmware β
Snapdragon 7c\+ Gen 3 Compute Firmware by Qualcomm
View all CVEs affecting Snapdragon 7c\+ Gen 3 Compute Firmware β
Snapdragon 8 Gen 1 Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 1 Mobile Firmware β
Snapdragon 8 Gen 1 Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 1 Mobile Firmware β
Snapdragon 8 Gen 2 Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 2 Mobile Firmware β
Snapdragon 8 Gen 2 Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 2 Mobile Firmware β
Snapdragon 8 Gen 3 Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 3 Mobile Firmware β
Snapdragon 855 Mobile Firmware by Qualcomm
Snapdragon 855 Mobile Firmware by Qualcomm
Snapdragon 860 Mobile Firmware by Qualcomm
Snapdragon 865 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 865 5g Mobile Firmware β
Snapdragon 865 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 865 5g Mobile Firmware β
Snapdragon 870 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 870 5g Mobile Firmware β
Snapdragon 888 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 888 5g Mobile Firmware β
Snapdragon 888 5g Mobile Firmware by Qualcomm
View all CVEs affecting Snapdragon 888 5g Mobile Firmware β
Snapdragon Auto 4g Modem Firmware by Qualcomm
View all CVEs affecting Snapdragon Auto 4g Modem Firmware β
Snapdragon Auto 5g Modem Rf Firmware by Qualcomm
View all CVEs affecting Snapdragon Auto 5g Modem Rf Firmware β
Snapdragon Auto 5g Modem Rf Gen 2 Firmware by Qualcomm
View all CVEs affecting Snapdragon Auto 5g Modem Rf Gen 2 Firmware β
Snapdragon W5\+ Gen 1 Wearable Firmware by Qualcomm
View all CVEs affecting Snapdragon W5\+ Gen 1 Wearable Firmware β
Snapdragon X24 Lte Modem Firmware by Qualcomm
View all CVEs affecting Snapdragon X24 Lte Modem Firmware β
Snapdragon X35 5g Modem Rf Firmware by Qualcomm
View all CVEs affecting Snapdragon X35 5g Modem Rf Firmware β
Snapdragon X50 5g Modem Rf Firmware by Qualcomm
View all CVEs affecting Snapdragon X50 5g Modem Rf Firmware β
Snapdragon X55 5g Modem Rf Firmware by Qualcomm
View all CVEs affecting Snapdragon X55 5g Modem Rf Firmware β
Snapdragon X65 5g Modem Rf Firmware by Qualcomm
View all CVEs affecting Snapdragon X65 5g Modem Rf Firmware β
Snapdragon X70 Modem Rf Firmware by Qualcomm
View all CVEs affecting Snapdragon X70 Modem Rf Firmware β
Snapdragon X72 5g Modem Rf Firmware by Qualcomm
View all CVEs affecting Snapdragon X72 5g Modem Rf Firmware β
Snapdragon X75 5g Modem Rf Firmware by Qualcomm
View all CVEs affecting Snapdragon X75 5g Modem Rf Firmware β
Video Collaboration Vc1 Platform Firmware by Qualcomm
View all CVEs affecting Video Collaboration Vc1 Platform Firmware β
β οΈ Risk & Real-World Impact
Worst Case
Complete service disruption of IKEv2 services, causing VPN connections to drop and preventing new secure connections from being established.
Likely Case
Temporary service interruption affecting IKEv2 sessions, requiring service restart to restore functionality.
If Mitigated
Minimal impact with proper network segmentation and monitoring in place to detect and block malicious traffic.
π― Exploit Status
Exploitation requires sending specially crafted IKEv2 packets to vulnerable systems
π οΈ Fix & Mitigation
β Official Fix
Patch Version: Check Qualcomm May 2024 security bulletin for specific patched versions
Vendor Advisory: https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2024-bulletin.html
Restart Required: Yes
Instructions:
1. Check Qualcomm May 2024 security bulletin for affected products. 2. Apply vendor-provided firmware updates. 3. Restart affected devices/services.
π§ Temporary Workarounds
Network filtering
allBlock or filter IKEv2 traffic from untrusted sources using firewalls or network ACLs
Disable IKEv2 if not needed
allUse alternative VPN protocols if IKEv2 functionality is not required
π§― If You Can't Patch
- Implement strict network segmentation to isolate IKEv2 services
- Deploy intrusion detection/prevention systems to monitor for malformed IKEv2 packets
π How to Verify
Check if Vulnerable:
Check device firmware version against Qualcomm's affected version list in May 2024 bulletin
Check Version:
Device-specific; typically 'getprop ro.build.version' or similar on Android devices
Verify Fix Applied:
Verify firmware version has been updated to patched version specified in Qualcomm bulletin
π‘ Detection & Monitoring
Log Indicators:
- Unexpected IKEv2 connection drops
- IKEv2 service crashes/restarts
- Malformed packet warnings in network logs
Network Indicators:
- Unusual IKEv2 traffic patterns
- Spike in IKEv2 informational requests
- Fragmented IKEv2 packets from single sources
SIEM Query:
Search for IKEv2 protocol anomalies or service disruption events in VPN/IKE logs