Vulnerabilities > CVE-2024-33037 - Buffer Over-read vulnerability in Qualcomm products

047910
CVSS 6.1 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
LOW
local
low complexity
qualcomm
CWE-126

Summary

Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.

Vulnerable Configurations

Part Description Count
OS
Qualcomm
51
Hardware
Qualcomm
51

Common Weakness Enumeration (CWE)