Vulnerability Description
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Ar8035 Firmware | - |
| Qualcomm | Ar8035 | - |
| Qualcomm | Csr8811 Firmware | - |
| Qualcomm | Csr8811 | - |
| Qualcomm | Fastconnect 6700 Firmware | - |
| Qualcomm | Fastconnect 6700 | - |
| Qualcomm | Fastconnect 6900 Firmware | - |
| Qualcomm | Fastconnect 6900 | - |
| Qualcomm | Fastconnect 7800 Firmware | - |
| Qualcomm | Fastconnect 7800 | - |
| Qualcomm | Immersive Home 214 Firmware | - |
| Qualcomm | Immersive Home 214 | - |
| Qualcomm | Immersive Home 216 Firmware | - |
| Qualcomm | Immersive Home 216 | - |
| Qualcomm | Immersive Home 316 Firmware | - |
| Qualcomm | Immersive Home 316 | - |
| Qualcomm | Immersive Home 318 Firmware | - |
| Qualcomm | Immersive Home 318 | - |
| Qualcomm | Immersive Home 3210 Firmware | - |
| Qualcomm | Immersive Home 3210 | - |
Related Weaknesses (CWE)
References
- https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-PatchVendor Advisory
FAQ
What is CVE-2024-45558?
CVE-2024-45558 is a vulnerability with a CVSS score of 7.5 (HIGH). Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
How severe is CVE-2024-45558?
CVE-2024-45558 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-45558?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Ar8035 Firmware, Qualcomm Ar8035, Qualcomm Csr8811 Firmware, Qualcomm Csr8811, Qualcomm Fastconnect 6700 Firmware.