CVE-2024-21456: Buffer Over-read in WLAN HOST
Published Jul 1, 2024
·Updated
Information Disclosure while parsing beacon frame in STA.
Affected Software
84 affected components
All of the following
Qualcomm Ar8035 Firmware
Qualcomm Ar8035
All of the following
Qualcomm Fastconnect 7800 Firmware
Qualcomm Fastconnect 7800
All of the following
Qualcomm Qam8255p Firmware
Qualcomm Qam8255p
All of the following
Qualcomm Qam8620p Firmware
Qualcomm Qam8620p
All of the following
Qualcomm Qam8650p Firmware
Qualcomm Qam8650p
All of the following
Qualcomm Qam8775p Firmware
Qualcomm Qam8775p
All of the following
Qualcomm Qamsrv1h Firmware
Qualcomm Qamsrv1h
All of the following
Qualcomm Qamsrv1m Firmware
Qualcomm Qamsrv1m
All of the following
Qualcomm Qca6554a Firmware
Qualcomm Qca6554a
All of the following
Qualcomm Qca6564au Firmware
Qualcomm Qca6564au
All of the following
Qualcomm Qca6574 Firmware
Qualcomm QCA6574
All of the following
Qualcomm Qca6574a Firmware
Qualcomm Qca6574a
All of the following
Qualcomm Qca6574au Firmware
Qualcomm QCA6574AU
All of the following
Qualcomm Qca6584au Firmware
Qualcomm QCA6584AU
All of the following
Qualcomm Qca6595 Firmware
Qualcomm Qca6595
All of the following
Qualcomm Qca6595au Firmware
Qualcomm Qca6595au
All of the following
Qualcomm Qca6678aq Firmware
Qualcomm Qca6678aq
All of the following
Qualcomm Qca6696 Firmware
Qualcomm Qca6696
All of the following
Qualcomm Qca6698aq Firmware
Qualcomm Qca6698aq
All of the following
Qualcomm Qca8081 Firmware
Qualcomm QCA8081
All of the following
Qualcomm Qca8337 Firmware
Qualcomm Qca8337
All of the following
Qualcomm Qcc2073 Firmware
Qualcomm Qcc2073
All of the following
Qualcomm Qcc2076 Firmware
Qualcomm Qcc2076
All of the following
Qualcomm Qcc710 Firmware
Qualcomm Qcc710
All of the following
Qualcomm Qcn6224 Firmware
Qualcomm Qcn6224
All of the following
Qualcomm Qcn6274 Firmware
Qualcomm Qcn6274
All of the following
Qualcomm Qfw7114 Firmware
Qualcomm Qfw7114
All of the following
Qualcomm Qfw7124 Firmware
Qualcomm Qfw7124
All of the following
Qualcomm Sa7255p Firmware
Qualcomm Sa7255p
All of the following
Qualcomm Sa7775p Firmware
Qualcomm Sa7775p
All of the following
Qualcomm Sa8255p Firmware
Qualcomm Sa8255p
All of the following
Qualcomm Sa8650p Firmware
Qualcomm Sa8650p
All of the following
Qualcomm Sa8770p Firmware
Qualcomm Sa8770p
All of the following
Qualcomm Sa8775p Firmware
Qualcomm Sa8775p
All of the following
Qualcomm Sa9000p Firmware
Qualcomm Sa9000p
All of the following
Qualcomm Snapdragon Auto 5g Modem-rf Gen 2 Firmware
Qualcomm Snapdragon Auto 5g Modem-rf Gen 2
All of the following
Qualcomm Snapdragon X72 5g Modem-rf System Firmware
Qualcomm Snapdragon X72 5g Modem-rf System
All of the following
Qualcomm Snapdragon X75 5g Modem-rf System Firmware
Qualcomm Snapdragon X75 5g Modem-rf System
All of the following
Qualcomm Srv1h Firmware
Qualcomm Srv1h
All of the following
Qualcomm Srv1l Firmware
Qualcomm Srv1l
All of the following
Qualcomm Srv1m Firmware
Qualcomm Srv1m
All of the following
Qualcomm Wcd9340 Firmware
Qualcomm Wcd9340
Remediation
Event History
Jul 1, 2024
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-21456?
CVE-2024-21456 has been categorized with a medium severity rating due to information disclosure vulnerabilities when parsing beacon frames.
2
How do I fix CVE-2024-21456?
To remediate CVE-2024-21456, it is recommended to update the affected firmware to the latest version provided by Qualcomm.
3
Which devices are affected by CVE-2024-21456?
CVE-2024-21456 affects multiple Qualcomm firmware versions including Ar8035, Fastconnect 7800, and several others.
4
What types of information could be disclosed due to CVE-2024-21456?
Vulnerabilities in CVE-2024-21456 may allow attackers to obtain sensitive information from the beacon frame parsing process.
5
Is there a workaround for CVE-2024-21456?
Currently, the recommended approach for CVE-2024-21456 is to apply the necessary firmware updates rather than relying on workarounds.