Vulnerability Description
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Ar8035 Firmware | - |
| Qualcomm | Ar8035 | - |
| Qualcomm | Csr8811 Firmware | - |
| Qualcomm | Csr8811 | - |
| Qualcomm | Fastconnect 6200 Firmware | - |
| Qualcomm | Fastconnect 6200 | - |
| Qualcomm | Fastconnect 6700 Firmware | - |
| Qualcomm | Fastconnect 6700 | - |
| Qualcomm | Fastconnect 6900 Firmware | - |
| Qualcomm | Fastconnect 6900 | - |
| Qualcomm | Fastconnect 7800 Firmware | - |
| Qualcomm | Fastconnect 7800 | - |
| Qualcomm | Flight Rb5 5G Platform Firmware | - |
| Qualcomm | Flight Rb5 5G Platform | - |
| Qualcomm | Immersive Home 214 Platform Firmware | - |
| Qualcomm | Immersive Home 214 Platform | - |
| Qualcomm | Immersive Home 216 Platform Firmware | - |
| Qualcomm | Immersive Home 216 Platform | - |
| Qualcomm | Immersive Home 316 Platform Firmware | - |
| Qualcomm | Immersive Home 316 Platform | - |
Related Weaknesses (CWE)
References
- https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bPatchVendor Advisory
FAQ
What is CVE-2024-33015?
CVE-2024-33015 is a vulnerability with a CVSS score of 7.5 (HIGH). Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
How severe is CVE-2024-33015?
CVE-2024-33015 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-33015?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Ar8035 Firmware, Qualcomm Ar8035, Qualcomm Csr8811 Firmware, Qualcomm Csr8811, Qualcomm Fastconnect 6200 Firmware.