CVE-2024-33073
📋 TL;DR
This vulnerability allows attackers to read sensitive information from Wi-Fi chipsets when parsing Multi-Link Device (MLD) information elements. It affects devices with Qualcomm Wi-Fi chipsets that haven't been patched. The information disclosure could reveal network configuration details or device capabilities.
💻 Affected Systems
- Qualcomm Wi-Fi chipsets and devices using them
📦 What is this software?
Flight Rb5 5g Platform Firmware by Qualcomm
Immersive Home 214 Platform Firmware by Qualcomm
View all CVEs affecting Immersive Home 214 Platform Firmware →
Immersive Home 216 Platform Firmware by Qualcomm
View all CVEs affecting Immersive Home 216 Platform Firmware →
Immersive Home 316 Platform Firmware by Qualcomm
View all CVEs affecting Immersive Home 316 Platform Firmware →
Immersive Home 318 Platform Firmware by Qualcomm
View all CVEs affecting Immersive Home 318 Platform Firmware →
Immersive Home 3210 Platform Firmware by Qualcomm
View all CVEs affecting Immersive Home 3210 Platform Firmware →
Immersive Home 326 Platform Firmware by Qualcomm
View all CVEs affecting Immersive Home 326 Platform Firmware →
Snapdragon 8 Gen 2 Mobile Platform Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 2 Mobile Platform Firmware →
Snapdragon 8 Gen 2 Mobile Platform Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 2 Mobile Platform Firmware →
Snapdragon 8 Gen 3 Mobile Platform Firmware by Qualcomm
View all CVEs affecting Snapdragon 8 Gen 3 Mobile Platform Firmware →
Snapdragon Ar2 Gen 1 Platform Firmware by Qualcomm
View all CVEs affecting Snapdragon Ar2 Gen 1 Platform Firmware →
Snapdragon Auto 5g Modem Rf Gen 2 Firmware by Qualcomm
View all CVEs affecting Snapdragon Auto 5g Modem Rf Gen 2 Firmware →
Snapdragon X65 5g Modem Rf System Firmware by Qualcomm
View all CVEs affecting Snapdragon X65 5g Modem Rf System Firmware →
Snapdragon X72 5g Modem Rf System Firmware by Qualcomm
View all CVEs affecting Snapdragon X72 5g Modem Rf System Firmware →
Snapdragon X75 5g Modem Rf System Firmware by Qualcomm
View all CVEs affecting Snapdragon X75 5g Modem Rf System Firmware →
Video Collaboration Vc3 Platform Firmware by Qualcomm
View all CVEs affecting Video Collaboration Vc3 Platform Firmware →
⚠️ Risk & Real-World Impact
Worst Case
Attackers could extract sensitive network configuration data, device capabilities, or potentially use the disclosed information to facilitate further attacks on the wireless network.
Likely Case
Information disclosure revealing BSS parameter change counts and MLD capabilities, which could help attackers profile networks or devices.
If Mitigated
Limited impact with proper network segmentation and monitoring, though information disclosure still occurs.
🎯 Exploit Status
Exploitation requires wireless proximity and knowledge of Wi-Fi protocol parsing vulnerabilities
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: Check Qualcomm October 2024 security bulletin for chipset-specific patches
Vendor Advisory: https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html
Restart Required: Yes
Instructions:
1. Check Qualcomm advisory for your specific chipset model. 2. Obtain updated firmware/drivers from device manufacturer. 3. Apply patches following manufacturer instructions. 4. Reboot affected devices.
🔧 Temporary Workarounds
Disable Multi-Link Operation
allIf supported, disable MLO/MLD features to prevent parsing of vulnerable information elements
Device-specific configuration commands vary by manufacturer
Network Segmentation
allSegment wireless networks to limit exposure of sensitive devices
🧯 If You Can't Patch
- Implement strict network monitoring for unusual Wi-Fi traffic patterns
- Consider replacing affected hardware with patched versions if critical systems are vulnerable
🔍 How to Verify
Check if Vulnerable:
Check device specifications for Qualcomm Wi-Fi chipsets and compare against Qualcomm's October 2024 security bulletin
Check Version:
Device-specific commands vary; typically 'iwconfig', 'ip link show', or manufacturer-specific tools
Verify Fix Applied:
Verify firmware/driver versions match patched versions listed in Qualcomm advisory
📡 Detection & Monitoring
Log Indicators:
- Unusual Wi-Fi driver/firmware errors
- MLD/BSS parameter parsing failures
Network Indicators:
- Abnormal MLD information element traffic
- Unexpected BSS parameter change broadcasts
SIEM Query:
Search for Wi-Fi driver crashes, MLD parsing errors, or Qualcomm chipset-specific error codes