CVE-2024-33015Buffer Over-read in INC Snapdragon

Severity
7.5HIGHNVD
EPSS
0.4%
top 39.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 5

Description

Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon195 versions+194

Patches

🔴Vulnerability Details

1
GHSA
GHSA-727j-8989-82f7: Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report2024-08-05

📋Vendor Advisories

1
Android
CVE-2024-33015: WLAN2024-08-01