CVE-2024-45558

HIGH

Qualcomm Ar8035 Firmware - Buffer Over-read

Title source: rule
STIX 2.1

Description

Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.

Scores

CVSS v3 7.5
EPSS 0.0031
EPSS Percentile 54.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-125 CWE-126
Status published
Products (50)
qualcomm/ar8035_firmware
qualcomm/csr8811_firmware
qualcomm/fastconnect_6700_firmware
qualcomm/fastconnect_6900_firmware
qualcomm/fastconnect_7800_firmware
qualcomm/immersive_home_214_firmware
qualcomm/immersive_home_216_firmware
qualcomm/immersive_home_316_firmware
qualcomm/immersive_home_318_firmware
qualcomm/immersive_home_3210_firmware
... and 40 more
Published Jan 06, 2025
Tracked Since Feb 18, 2026