6.1

CVE-2024-33037

Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.

Data is provided by the National Vulnerability Database (NVD)
QualcommC-v2x 9150 Firmware Version-
   QualcommC-v2x 9150 Version-
QualcommQam8295p Firmware Version-
   QualcommQam8295p Version-
QualcommQca6174a Firmware Version-
   QualcommQca6174a Version-
QualcommQca6391 Firmware Version-
   QualcommQca6391 Version-
QualcommQca6426 Firmware Version-
   QualcommQca6426 Version-
QualcommQca6436 Firmware Version-
   QualcommQca6436 Version-
QualcommQca6574au Firmware Version-
   QualcommQca6574au Version-
QualcommQca6696 Firmware Version-
   QualcommQca6696 Version-
QualcommQca8337 Firmware Version-
   QualcommQca8337 Version-
QualcommQcn9074 Firmware Version-
   QualcommQcn9074 Version-
QualcommQcs410 Firmware Version-
   QualcommQcs410 Version-
QualcommQcs610 Firmware Version-
   QualcommQcs610 Version-
QualcommQsm8250 Firmware Version-
   QualcommQsm8250 Version-
QualcommSa6145p Firmware Version-
   QualcommSa6145p Version-
QualcommSa6150p Firmware Version-
   QualcommSa6150p Version-
QualcommSa6155p Firmware Version-
   QualcommSa6155p Version-
QualcommSa8145p Firmware Version-
   QualcommSa8145p Version-
QualcommSa8150p Firmware Version-
   QualcommSa8150p Version-
QualcommSa8155p Firmware Version-
   QualcommSa8155p Version-
QualcommSa8195p Firmware Version-
   QualcommSa8195p Version-
QualcommSa8295p Firmware Version-
   QualcommSa8295p Version-
QualcommSa8530p Firmware Version-
   QualcommSa8530p Version-
QualcommSa8540p Firmware Version-
   QualcommSa8540p Version-
QualcommSa9000p Firmware Version-
   QualcommSa9000p Version-
QualcommSd865 5g Firmware Version-
   QualcommSd865 5g Version-
QualcommSdx55 Firmware Version-
   QualcommSdx55 Version-
QualcommSw5100 Firmware Version-
   QualcommSw5100 Version-
QualcommSw5100p Firmware Version-
   QualcommSw5100p Version-
QualcommSxr2130 Firmware Version-
   QualcommSxr2130 Version-
QualcommWcd9341 Firmware Version-
   QualcommWcd9341 Version-
QualcommWcd9370 Firmware Version-
   QualcommWcd9370 Version-
QualcommWcd9380 Firmware Version-
   QualcommWcd9380 Version-
QualcommWcn3660b Firmware Version-
   QualcommWcn3660b Version-
QualcommWcn3680b Firmware Version-
   QualcommWcn3680b Version-
QualcommWcn3950 Firmware Version-
   QualcommWcn3950 Version-
QualcommWcn3980 Firmware Version-
   QualcommWcn3980 Version-
QualcommWcn3988 Firmware Version-
   QualcommWcn3988 Version-
QualcommWsa8810 Firmware Version-
   QualcommWsa8810 Version-
QualcommWsa8815 Firmware Version-
   QualcommWsa8815 Version-
QualcommWsa8830 Firmware Version-
   QualcommWsa8830 Version-
QualcommWsa8835 Firmware Version-
   QualcommWsa8835 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.059
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
product-security@qualcomm.com 6.1 1.8 4.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
CWE-126 Buffer Over-read

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.