CVE-2024-33018
📋 TL;DR
This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted TID-to-link mapping action frames to affected Wi-Fi devices. The vulnerability affects Qualcomm Wi-Fi chipsets and devices using them, potentially impacting smartphones, routers, IoT devices, and other wireless equipment.
💻 Affected Systems
- Qualcomm Wi-Fi chipsets and devices using them
📦 What is this software?
Immersive Home 214 Platform Firmware by Qualcomm
View all CVEs affecting Immersive Home 214 Platform Firmware →
Immersive Home 216 Platform Firmware by Qualcomm
View all CVEs affecting Immersive Home 216 Platform Firmware →
Immersive Home 316 Platform Firmware by Qualcomm
View all CVEs affecting Immersive Home 316 Platform Firmware →
Immersive Home 318 Platform Firmware by Qualcomm
View all CVEs affecting Immersive Home 318 Platform Firmware →
Immersive Home 3210 Platform Firmware by Qualcomm
View all CVEs affecting Immersive Home 3210 Platform Firmware →
Immersive Home 326 Platform Firmware by Qualcomm
View all CVEs affecting Immersive Home 326 Platform Firmware →
Snapdragon 8 Gen 2 Mobile Platform Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 2 Mobile Platform Firmware →
Snapdragon 8 Gen 2 Mobile Platform Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 2 Mobile Platform Firmware →
Snapdragon 8 Gen 3 Mobile Platform Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 3 Mobile Platform Firmware →
Snapdragon Ar2 Gen 1 Platform Firmware by Qualcomm
View all CVEs affecting Snapdragon Ar2 Gen 1 Platform Firmware →
Snapdragon Auto 5g Modem Rf Gen 2 Firmware by Qualcomm
View all CVEs affecting Snapdragon Auto 5g Modem Rf Gen 2 Firmware →
Snapdragon X65 5g Modem Rf System Firmware by Qualcomm
View all CVEs affecting Snapdragon X65 5g Modem Rf System Firmware →
Snapdragon X72 5g Modem Rf System Firmware by Qualcomm
View all CVEs affecting Snapdragon X72 5g Modem Rf System Firmware →
Snapdragon X75 5g Modem Rf System Firmware by Qualcomm
View all CVEs affecting Snapdragon X75 5g Modem Rf System Firmware →
⚠️ Risk & Real-World Impact
Worst Case
Permanent device crash requiring physical restart, disrupting all wireless connectivity on affected devices.
Likely Case
Temporary service disruption where affected Wi-Fi interfaces reset or become unresponsive until frames stop or system restarts.
If Mitigated
Minimal impact with proper network segmentation and monitoring; affected devices may experience brief connectivity interruptions.
🎯 Exploit Status
Exploitation requires sending crafted 802.11 action frames; attacker needs to be within wireless range of target
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: Check device manufacturer updates; Qualcomm has provided fixes to OEMs
Vendor Advisory: https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html
Restart Required: Yes
Instructions:
1. Check with device manufacturer for security updates. 2. Apply firmware/OS updates from manufacturer. 3. Reboot device after update.
🔧 Temporary Workarounds
Disable Wi-Fi if not needed
allTurn off Wi-Fi interfaces on critical devices that don't require wireless connectivity
Implement wireless intrusion prevention
allDeploy WIPS to detect and block malicious 802.11 action frames
🧯 If You Can't Patch
- Segment wireless networks from critical infrastructure
- Monitor for unusual wireless frame patterns and DoS events
🔍 How to Verify
Check if Vulnerable:
Check device manufacturer security bulletins for your specific model; verify Qualcomm chipset version
Check Version:
Device-specific (e.g., Android: Settings > About phone; Linux: check driver/firmware versions)
Verify Fix Applied:
Confirm latest firmware/OS version is installed and check manufacturer's patched version list
📡 Detection & Monitoring
Log Indicators:
- Wi-Fi interface resets
- Driver/firmware crash logs
- Unexpected disconnections
Network Indicators:
- Unusual 802.11 action frame patterns
- Multiple TID-to-link mapping frames from single source
SIEM Query:
Search for Wi-Fi interface error events or driver crash events in system logs