CVE-2024-33011
HIGHCVSS 7.5/10EPSS 0.28%
Last modified
CVE-2024-33011 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Wsa8845h Firmware | All versions |
| Qualcomm | Wsa8845 Firmware | All versions |
| Qualcomm | Wsa8840 Firmware | All versions |
| Qualcomm | Wsa8835 Firmware | All versions |
| Qualcomm | Wsa8832 Firmware | All versions |
| Qualcomm | Wsa8830 Firmware | All versions |
| Qualcomm | Wsa8815 Firmware | All versions |
| Qualcomm | Wsa8810 Firmware | All versions |
| Qualcomm | Wcn6740 Firmware | All versions |
| Qualcomm | Wcn3990 Firmware | All versions |
| Qualcomm | Wcn3988 Firmware | All versions |
| Qualcomm | Wcn3980 Firmware | All versions |
| Qualcomm | Wcn3950 Firmware | All versions |
| Qualcomm | Wcd9395 Firmware | All versions |
| Qualcomm | Wcd9390 Firmware | All versions |
| Qualcomm | Wcd9385 Firmware | All versions |
| Qualcomm | Wcd9380 Firmware | All versions |
| Qualcomm | Wcd9375 Firmware | All versions |
| Qualcomm | Wcd9370 Firmware | All versions |
| Qualcomm | Wcd9341 Firmware | All versions |
| Qualcomm | Wcd9340 Firmware | All versions |
| Qualcomm | Wcd9335 Firmware | All versions |
| Qualcomm | Vision Intelligence 400 Platform Firmware | All versions |
| Qualcomm | Talynplus Firmware | All versions |
| Qualcomm | Sxr2250p Firmware | All versions |
| Qualcomm | Sxr2230p Firmware | All versions |
| Qualcomm | Sxr1230p Firmware | All versions |
| Qualcomm | Sw5100p Firmware | All versions |
| Qualcomm | Sw5100 Firmware | All versions |
| Qualcomm | Ssg2125p Firmware | All versions |
| Qualcomm | Ssg2115p Firmware | All versions |
| Qualcomm | Srv1m Firmware | All versions |
| Qualcomm | Srv1l Firmware | All versions |
| Qualcomm | Srv1h Firmware | All versions |
| Qualcomm | Snapdragon X75 5g Modem-Rf System Firmware | All versions |
| Qualcomm | Snapdragon X72 5g Modem-Rf System Firmware | All versions |
| Qualcomm | Snapdragon X65 5g Modem-Rf System Firmware | All versions |
| Qualcomm | Snapdragon X62 5g Modem-Rf System Firmware | All versions |
| Qualcomm | Snapdragon X35 5g Modem-Rf System Firmware | All versions |
| Qualcomm | Snapdragon W5\+ Gen 1 Wearable Platform Firmware | All versions |
| Qualcomm | Snapdragon Auto 5g Modem-Rf Gen 2 Firmware | All versions |
| Qualcomm | Snapdragon Auto 5g Modem-Rf Firmware | All versions |
| Qualcomm | Snapdragon Ar2 Gen 1 Platform Firmware | All versions |
| Qualcomm | Snapdragon 888\+ 5g Mobile Platform \(Sm8350-Ac\) Firmware | All versions |
| Qualcomm | Snapdragon 888 5g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8\+ Gen 2 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8\+ Gen 1 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 3 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 2 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 1 Mobile Platform Firmware | All versions |
Showing 50 of 249 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-33011?
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
How severe is CVE-2024-33011?
CVE-2024-33011 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.28% probability of exploitation in the next 30 days.
How do I fix CVE-2024-33011?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-33006 An unauthenticated attacker can upload a malicious file to …9.6
- CVE-2024-33007PDFViewer is a control delivered as part of SAPUI5 product w…3.5
- CVE-2024-33008SAP Replication Server allows an attacker to use gateway for…4.9
- CVE-2024-33009SAP Global Label Management is vulnerable to SQL injection. …4.2
- CVE-2024-3301An unsafe .NET object deserialization vulnerability in DELMI…8.5
- CVE-2024-33010Transient DOS while parsing fragments of MBSSID IE from beac…7.5
- CVE-2024-33012Transient DOS while parsing the multiple MBSSID IEs from the…7.5
- CVE-2024-33013Transient DOS when driver accesses the ML IE memory and offs…7.5
- CVE-2024-33014Transient DOS while parsing ESP IE from beacon/probe respons…7.5
- CVE-2024-33015Transient DOS while parsing SCAN RNR IE when bytes received …7.5
- CVE-2024-33016memory corruption when an invalid firehose patch command is …6.8
- CVE-2024-33018Transient DOS while parsing the received TID-to-link mapping…7.5
Are you affected by CVE-2024-33011?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
