CVE-2024-33067

MEDIUM

Qualcomm Ar8035 Firmware - Buffer Over-read

Title source: rule
STIX 2.1

Description

Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.

Scores

CVSS v3 6.1
EPSS 0.0007
EPSS Percentile 22.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125 CWE-126
Status published
Products (50)
qualcomm/ar8035_firmware
qualcomm/c-v2x_9150_firmware
qualcomm/csrb31024_firmware
qualcomm/fastconnect_6800_firmware
qualcomm/fastconnect_6900_firmware
qualcomm/fastconnect_7800_firmware
qualcomm/msm8996au_firmware
qualcomm/qam8295p_firmware
qualcomm/qca6310_firmware
qualcomm/qca6320_firmware
... and 40 more
Published Jan 06, 2025
Tracked Since Feb 18, 2026