7.5
CVE-2024-33071
- EPSS 0.32%
- Veröffentlicht 07.10.2024 13:15:13
- Zuletzt bearbeitet 16.10.2024 19:41:46
- Erkennungen
Buffer Over-read in WLAN Host Communication
Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qualcomm ≫ Mdm9628 Firmware Version -
Qualcomm ≫ Qca6564a Firmware Version -
Qualcomm ≫ Qca6564au Firmware Version -
Qualcomm ≫ Qca6574a Firmware Version -
Qualcomm ≫ Qca6574au Firmware Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.244 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Qualcomm | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CWE-126 Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html