Loading HuntDB...

CVE-2024-33045

HIGH
Published 2024-09-02T10:22:37.525Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2024-33045. We'll provide specific mitigation strategies based on your environment and risk profile.

CVSS Score

V3.1
8.4
/10
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score Metrics
Exploitability: N/A Impact: N/A

EPSS Score

v2025.03.14
0.000
probability
of exploitation in the wild

There is a 0.0% chance that this vulnerability will be exploited in the wild within the next 30 days.

Updated: 2025-06-25
Exploit Probability
Percentile: 0.102
Higher than 10.2% of all CVEs

Attack Vector Metrics

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED

Impact Metrics

Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Description

Memory corruption when BTFM client sends new messages over Slimbus to ADSP.

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

Affected Products

Affected Versions:

AR8035 CSRA6620 CSRA6640 FastConnect 6200 FastConnect 6700 FastConnect 6900 FastConnect 7800 Flight RB5 5G Platform FSM10055 FSM10056 FSM20055 FSM20056 Immersive Home 3210 Platform Immersive Home 326 Platform IPQ9574 MDM9628 QAM8255P QAM8295P QAM8620P QAM8650P QAM8775P QAMSRV1H QAMSRV1M QCA6174A QCA6310 QCA6320 QCA6391 QCA6564A QCA6564AU QCA6574 QCA6574A QCA6574AU QCA6584AU QCA6595 QCA6595AU QCA6678AQ QCA6688AQ QCA6696 QCA6698AQ QCA6797AQ QCA8081 QCA8337 QCA9367 QCA9377 QCM4325 QCM4490 QCM5430 QCM6125 QCM6490 QCM8550 QCN6024 QCN9011 QCN9012 QCN9024 QCN9274 QCS410 QCS4490 QCS5430 QCS610 QCS6125 QCS6490 QCS7230 QCS8250 QCS8550 QDU1000 QDU1010 QDU1110 QDU1210 QDX1010 QDX1011 QEP8111 QRB5165M QRB5165N QRU1032 QRU1052 QRU1062 QSM8350 Qualcomm Video Collaboration VC1 Platform Qualcomm Video Collaboration VC3 Platform Qualcomm Video Collaboration VC5 Platform Robotics RB5 Platform SA4150P SA4155P SA6145P SA6150P SA6155P SA7255P SA7775P SA8145P SA8150P SA8155P SA8195P SA8255P SA8295P SA8530P SA8540P SA8620P SA8650P SA8770P SA8775P SA9000P SD 8 Gen1 5G SD835 SD888 SDX61 SG4150P SG8275P SM4635 SM6370 SM7315 SM7325P SM8550P SM8635 Smart Audio 400 Platform Snapdragon 4 Gen 1 Mobile Platform Snapdragon 4 Gen 2 Mobile Platform Snapdragon 460 Mobile Platform Snapdragon 480 5G Mobile Platform Snapdragon 480+ 5G Mobile Platform (SM4350-AC) Snapdragon 662 Mobile Platform Snapdragon 680 4G Mobile Platform Snapdragon 685 4G Mobile Platform (SM6225-AD) Snapdragon 695 5G Mobile Platform Snapdragon 778G 5G Mobile Platform Snapdragon 778G+ 5G Mobile Platform (SM7325-AE) Snapdragon 780G 5G Mobile Platform Snapdragon 782G Mobile Platform (SM7325-AF) Snapdragon 7c+ Gen 3 Compute Snapdragon 8 Gen 1 Mobile Platform Snapdragon 8 Gen 2 Mobile Platform Snapdragon 8 Gen 3 Mobile Platform Snapdragon 8+ Gen 1 Mobile Platform Snapdragon 8+ Gen 2 Mobile Platform Snapdragon 835 Mobile PC Platform Snapdragon 888 5G Mobile Platform Snapdragon 888+ 5G Mobile Platform (SM8350-AC) Snapdragon AR2 Gen 1 Platform Snapdragon Auto 5G Modem-RF Snapdragon Auto 5G Modem-RF Gen 2 Snapdragon W5+ Gen 1 Wearable Platform Snapdragon X12 LTE Modem Snapdragon X35 5G Modem-RF System Snapdragon X62 5G Modem-RF System Snapdragon X65 5G Modem-RF System SRV1H SRV1L SRV1M SSG2115P SSG2125P SW5100 SW5100P SXR1230P SXR2230P SXR2250P TalynPlus Vision Intelligence 400 Platform WCD9335 WCD9340 WCD9341 WCD9370 WCD9375 WCD9378 WCD9380 WCD9385 WCD9390 WCD9395 WCN3950 WCN3980 WCN3988 WCN3990 WCN6740 WCN6755 WSA8810 WSA8815 WSA8830 WSA8832 WSA8835 WSA8840 WSA8845 WSA8845H

EU Vulnerability Database

Monitored by ENISA for EU cybersecurity

EU Coordination

EU Coordinated

Exploitation Status

No Known Exploitation

ENISA Analysis

Malicious code in bioql (PyPI)

Affected Products (ENISA)

qualcomm, inc.
snapdragon

ENISA Scoring

CVSS Score (3.1)

8.4
/10
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.040
probability

Data provided by ENISA EU Vulnerability Database. Last updated: October 3, 2025

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed HIGH

GHSA-mfmc-fmc9-6ph8

Advisory Details

Memory corruption when BTFM client sends new messages over Slimbus to ADSP.

CVSS Scoring

CVSS Score

7.5

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Advisory provided by GitHub Security Advisory Database. Published: September 2, 2024, Modified: September 2, 2024

References

Published: 2024-09-02T10:22:37.525Z
Last Modified: 2024-09-05T03:56:09.849Z
Copied to clipboard!