SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-33015

Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.

HIGH 7.5EPSS 0.28%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
0.28% probability · 21th percentile
CISA KEV
Not listed
Weakness
CWE-126, CWE-125
Affected
qualcomm/ar8035 firmware · qualcomm/csr8811 firmware · qualcomm/fastconnect 6200 firmware · qualcomm/fastconnect 6700 firmware · qualcomm/fastconnect 6900 firmware · qualcomm/fastconnect 7800 firmware · qualcomm/flight rb5 5g platform firmware · qualcomm/immersive home 214 platform firmware · qualcomm/immersive home 216 platform firmware · qualcomm/immersive home 316 platform firmware · qualcomm/immersive home 318 platform firmware · qualcomm/immersive home 3210 platform firmware · qualcomm/immersive home 326 platform firmware · qualcomm/ipq5010 firmware · qualcomm/ipq5028 firmware · qualcomm/ipq5300 firmware · qualcomm/ipq5302 firmware · qualcomm/ipq5312 firmware · qualcomm/ipq5332 firmware · qualcomm/ipq6000 firmware · +40 more
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.