CVE-2024-49846Critical
CVE
CVE
National Vulnerability Database
NVD is the U.S. government repository of standards-based vulnerability management data, built on top of the MITRE CVE list. Every record includes CPE applicability statements, CVSS v2 and v3.x base scores, CWE mappings and cross-references to advisories.
Region
US
Updates
15 min
License
Public Domain
Comprehensive catalog of publicly disclosed vulnerabilities with CPE matches, CVSS scoring and reference URLs. De-facto standard for cross-vendor correlation.
https://nvd.nist.gov →Share link
Anyone with the link can open this vulnerability.
Memory corruption while decoding of OTA messages from T3448 IE.
CVSS
9.1
Critical
EPSS
0.00
p14
Published
2024-01-01
Updated
2024-01-01
Description
Memory corruption while decoding of OTA messages from T3448 IE.
Tags · CWE
Pre-auth
CWE-126
CWE-126VariantDraft
Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
https://cwe.mitre.org/data/definitions/126.html →Open in CWE collection →Affected products
Ar8035_firmwareFastconnect_7800_firmwareQca6574au_firmwareQca6595au_firmwareQca6678aq_firmwareQca6688aq_firmwareQca6698aq_firmwareQca8081_firmwareQca8337_firmwareQcc710_firmwareQcn6224_firmwareQcn6274_firmwareQfw7114_firmwareQfw7124_firmwareSdx80m_firmwareSm8750_firmwareSm8750p_firmwareSnapdragon_auto_5g_modem-rf_gen_2_firmwareSnapdragon_w5+_gen_1_wearable_firmwareSnapdragon_x72_5g_modem-rf_system_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.002 · p14
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
| Product | Vendor | Status |
|---|---|---|
| ar8035_firmware | * | Tracked |
| fastconnect_7800_firmware | * | Tracked |
| qca6574au_firmware | * | Tracked |
| qca6595au_firmware | * | Tracked |
| qca6678aq_firmware | * | Tracked |
| qca6688aq_firmware | * | Tracked |
| qca6698aq_firmware | * | Tracked |
| qca8081_firmware | * | Tracked |
| qca8337_firmware | * | Tracked |
| qcc710_firmware | * | Tracked |
| qcn6224_firmware | * | Tracked |
| qcn6274_firmware | * | Tracked |
| qfw7114_firmware | * | Tracked |
| qfw7124_firmware | * | Tracked |
| sdx80m_firmware | * | Tracked |
| sm8750_firmware | * | Tracked |
| sm8750p_firmware | * | Tracked |
| snapdragon_auto_5g_modem-rf_gen_2_firmware | * | Tracked |
| snapdragon_w5+_gen_1_wearable_firmware | * | Tracked |
| snapdragon_x72_5g_modem-rf_system_firmware | * | Tracked |
Showing first 20 of 31
Source databases
CVE
CVE
National Vulnerability Database
NVD is the U.S. government repository of standards-based vulnerability management data, built on top of the MITRE CVE list. Every record includes CPE applicability statements, CVSS v2 and v3.x base scores, CWE mappings and cross-references to advisories.
Region
US
Updates
15 min
License
Public Domain
Comprehensive catalog of publicly disclosed vulnerabilities with CPE matches, CVSS scoring and reference URLs. De-facto standard for cross-vendor correlation.
https://nvd.nist.gov →