SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-45558

Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.

HIGH 7.5EPSS 0.36%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
0.36% probability · 30th percentile
CISA KEV
Not listed
Weakness
CWE-126, CWE-125
Affected
qualcomm/ar8035 firmware · qualcomm/csr8811 firmware · qualcomm/fastconnect 6700 firmware · qualcomm/fastconnect 6900 firmware · qualcomm/fastconnect 7800 firmware · qualcomm/immersive home 214 firmware · qualcomm/immersive home 216 firmware · qualcomm/immersive home 316 firmware · qualcomm/immersive home 318 firmware · qualcomm/immersive home 3210 firmware · qualcomm/immersive home 326 firmware · qualcomm/ipq5010 firmware · qualcomm/ipq5028 firmware · qualcomm/ipq5300 firmware · qualcomm/ipq5302 firmware · qualcomm/ipq5312 firmware · qualcomm/ipq5332 firmware · qualcomm/ipq6000 firmware · qualcomm/ipq6010 firmware · qualcomm/ipq6018 firmware · +40 more
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.