CVE-2024-33073
HIGHCVSS 8.2/10EPSS 0.34%
Last modified
CVE-2024-33073 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Wsa8845h Firmware | All versions |
| Qualcomm | Wsa8845 Firmware | All versions |
| Qualcomm | Wsa8840 Firmware | All versions |
| Qualcomm | Wsa8835 Firmware | All versions |
| Qualcomm | Wsa8832 Firmware | All versions |
| Qualcomm | Wsa8830 Firmware | All versions |
| Qualcomm | Wcd9395 Firmware | All versions |
| Qualcomm | Wcd9390 Firmware | All versions |
| Qualcomm | Wcd9385 Firmware | All versions |
| Qualcomm | Wcd9380 Firmware | All versions |
| Qualcomm | Wcd9375 Firmware | All versions |
| Qualcomm | Wcd9370 Firmware | All versions |
| Qualcomm | Wcd9340 Firmware | All versions |
| Qualcomm | Sxr2250p Firmware | All versions |
| Qualcomm | Sxr2230p Firmware | All versions |
| Qualcomm | Sxr1230p Firmware | All versions |
| Qualcomm | Ssg2125p Firmware | All versions |
| Qualcomm | Ssg2115p Firmware | All versions |
| Qualcomm | Srv1m Firmware | All versions |
| Qualcomm | Srv1l Firmware | All versions |
| Qualcomm | Srv1h Firmware | All versions |
| Qualcomm | Snapdragon X75 5g Modem-Rf System Firmware | All versions |
| Qualcomm | Snapdragon X72 5g Modem-Rf System Firmware | All versions |
| Qualcomm | Snapdragon X65 5g Modem-Rf System Firmware | All versions |
| Qualcomm | Snapdragon Auto 5g Modem-Rf Gen 2 Firmware | All versions |
| Qualcomm | Snapdragon Ar2 Gen 1 Platform Firmware | All versions |
| Qualcomm | Snapdragon 8\+ Gen 2 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 3 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 8 Gen 2 Mobile Platform Firmware | All versions |
| Qualcomm | Sm8550p Firmware | All versions |
| Qualcomm | Sg8275p Firmware | All versions |
| Qualcomm | Sdx65m Firmware | All versions |
| Qualcomm | Sdx55 Firmware | All versions |
| Qualcomm | Sa9000p Firmware | All versions |
| Qualcomm | Sa8775p Firmware | All versions |
| Qualcomm | Sa8770p Firmware | All versions |
| Qualcomm | Sa8650p Firmware | All versions |
| Qualcomm | Sa8620p Firmware | All versions |
| Qualcomm | Sa8295p Firmware | All versions |
| Qualcomm | Sa8255p Firmware | All versions |
| Qualcomm | Sa8195p Firmware | All versions |
| Qualcomm | Sa8155p Firmware | All versions |
| Qualcomm | Sa7775p Firmware | All versions |
| Qualcomm | Sa7255p Firmware | All versions |
| Qualcomm | Sa6155p Firmware | All versions |
| Qualcomm | Robotics Rb5 Platform Firmware | All versions |
| Qualcomm | Video Collaboration Vc5 Platform Firmware | All versions |
| Qualcomm | Video Collaboration Vc3 Platform Firmware | All versions |
| Qualcomm | Qrb5165n Firmware | All versions |
| Qualcomm | Qfw7124 Firmware | All versions |
Showing 50 of 159 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-33073?
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
How severe is CVE-2024-33073?
CVE-2024-33073 has a CVSS score of 8.2/10 (HIGH severity). The EPSS model estimates a 0.34% probability of exploitation in the next 30 days.
How do I fix CVE-2024-33073?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-33067Information disclosure while invoking callback function of s…5.5
- CVE-2024-33068Transient DOS while parsing fragments of MBSSID IE from beac…6.5
- CVE-2024-33069Transient DOS when transmission of management frame sent by …7.5
- CVE-2024-3307The HT Mega – Absolute Addons For Elementor plugin for WordP…5.4
- CVE-2024-33070Transient DOS while parsing ESP IE from beacon/probe respons…7.5
- CVE-2024-33071Transient DOS while parsing the MBSSID IE from the beacons w…7.5
- CVE-2024-33078Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user…9.8
- CVE-2024-3308The HT Mega – Absolute Addons For Elementor plugin for WordP…5.4
- CVE-2024-3309The Qi Addons For Elementor plugin for WordPress is vulnerab…5.4
- CVE-2024-33101A stored cross-site scripting (XSS) vulnerability in the com…6.1
- CVE-2024-33102A stored cross-site scripting (XSS) vulnerability in the com…5.4
- CVE-2024-33103An arbitrary file upload vulnerability in the Media Manager …6.1
Are you affected by CVE-2024-33073?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
