Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
History

Mon, 02 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm c-v2x 9150 Firmware
Qualcomm fastconnect 6800 Firmware
Qualcomm fastconnect 6900 Firmware
Qualcomm qam8295p Firmware
Qualcomm qca6174a Firmware
Qualcomm qca6391 Firmware
Qualcomm qca6426 Firmware
Qualcomm qca6436 Firmware
Qualcomm qca6574au Firmware
Qualcomm qca6696 Firmware
Qualcomm qca8337 Firmware
Qualcomm qcn9074 Firmware
Qualcomm qcs410 Firmware
Qualcomm qcs610 Firmware
Qualcomm qsm8250 Firmware
Qualcomm qualcomm Video Collaboration Vc1 Platform Firmware
Qualcomm qualcomm Video Collaboration Vc3 Platform Firmware
Qualcomm sa6145p Firmware
Qualcomm sa6150p Firmware
Qualcomm sa6155p Firmware
Qualcomm sa8145p Firmware
Qualcomm sa8150p Firmware
Qualcomm sa8155p Firmware
Qualcomm sa8195p Firmware
Qualcomm sa8295p Firmware
Qualcomm sa8530p Firmware
Qualcomm sa8540p Firmware
Qualcomm sa9000p Firmware
Qualcomm sd865 5g Firmware
Qualcomm sdx55 Firmware
Qualcomm snapdragon 865 5g Mobile Platform Firmware
Qualcomm snapdragon X55 5g Modem-rf System Firmware
Qualcomm snapdragon Xr2 5g Platform Firmware
Qualcomm sw5100 Firmware
Qualcomm sw5100p Firmware
Qualcomm sxr2130 Firmware
Qualcomm wcd9341 Firmware
Qualcomm wcd9370 Firmware
Qualcomm wcd9380 Firmware
Qualcomm wcn3660b Firmware
Qualcomm wcn3680b Firmware
Qualcomm wcn3950 Firmware
Qualcomm wcn3980 Firmware
Qualcomm wcn3988 Firmware
Qualcomm wsa8810 Firmware
Qualcomm wsa8815 Firmware
Qualcomm wsa8830 Firmware
Qualcomm wsa8835 Firmware
CPEs cpe:2.3:o:qualcomm:c-v2x_9150_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qam8295p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca6174a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca6391_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca6426_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca6436_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca6696_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca8337_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qcn9074_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qcs410_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qcs610_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qsm8250_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qualcomm_video_collaboration_vc1_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qualcomm_video_collaboration_vc3_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa6145p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa6150p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa6155p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8145p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8150p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8155p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8195p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8295p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8530p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa8540p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sa9000p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd865_5g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sdx55_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_865_5g_mobile_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_x55_5g_modem-rf_system_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_xr2_5g_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sw5100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sw5100p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sxr2130_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9341_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9370_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3660b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3680b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3950_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3980_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn3988_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8810_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8815_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*
Vendors & Products Qualcomm
Qualcomm c-v2x 9150 Firmware
Qualcomm fastconnect 6800 Firmware
Qualcomm fastconnect 6900 Firmware
Qualcomm qam8295p Firmware
Qualcomm qca6174a Firmware
Qualcomm qca6391 Firmware
Qualcomm qca6426 Firmware
Qualcomm qca6436 Firmware
Qualcomm qca6574au Firmware
Qualcomm qca6696 Firmware
Qualcomm qca8337 Firmware
Qualcomm qcn9074 Firmware
Qualcomm qcs410 Firmware
Qualcomm qcs610 Firmware
Qualcomm qsm8250 Firmware
Qualcomm qualcomm Video Collaboration Vc1 Platform Firmware
Qualcomm qualcomm Video Collaboration Vc3 Platform Firmware
Qualcomm sa6145p Firmware
Qualcomm sa6150p Firmware
Qualcomm sa6155p Firmware
Qualcomm sa8145p Firmware
Qualcomm sa8150p Firmware
Qualcomm sa8155p Firmware
Qualcomm sa8195p Firmware
Qualcomm sa8295p Firmware
Qualcomm sa8530p Firmware
Qualcomm sa8540p Firmware
Qualcomm sa9000p Firmware
Qualcomm sd865 5g Firmware
Qualcomm sdx55 Firmware
Qualcomm snapdragon 865 5g Mobile Platform Firmware
Qualcomm snapdragon X55 5g Modem-rf System Firmware
Qualcomm snapdragon Xr2 5g Platform Firmware
Qualcomm sw5100 Firmware
Qualcomm sw5100p Firmware
Qualcomm sxr2130 Firmware
Qualcomm wcd9341 Firmware
Qualcomm wcd9370 Firmware
Qualcomm wcd9380 Firmware
Qualcomm wcn3660b Firmware
Qualcomm wcn3680b Firmware
Qualcomm wcn3950 Firmware
Qualcomm wcn3980 Firmware
Qualcomm wcn3988 Firmware
Qualcomm wsa8810 Firmware
Qualcomm wsa8815 Firmware
Qualcomm wsa8830 Firmware
Qualcomm wsa8835 Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Dec 2024 10:30:00 +0000

Type Values Removed Values Added
Description Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
Title Buffer Over-read in Neural Processing Unit
Weaknesses CWE-126
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published: 2024-12-02T10:18:40.468Z

Updated: 2024-12-02T15:43:14.290Z

Reserved: 2024-04-23T04:42:06.931Z

Link: CVE-2024-33037

cve-icon Vulnrichment

Updated: 2024-12-02T15:42:21.853Z

cve-icon NVD

Status : Received

Published: 2024-12-02T11:15:07.753

Modified: 2024-12-02T11:15:07.753

Link: CVE-2024-33037

cve-icon Redhat

No data.