Attacker Value
Unknown
0
CVE-2024-38404
0
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2024-38404
(Last updated February 06, 2025) ▾
MITRE ATT&CK
Log in to add MITRE ATT&CK tag
Add MITRE ATT&CK tactics and techniques that apply to this CVE.
MITRE ATT&CK
Select the MITRE ATT&CK Tactics that apply to this CVE
Collection
Select any Techniques used:
Command and Control
Select any Techniques used:
Credential Access
Select any Techniques used:
Defense Evasion
Select any Techniques used:
Discovery
Select any Techniques used:
Execution
Select any Techniques used:
Exfiltration
Select any Techniques used:
Impact
Select any Techniques used:
Initial Access
Select any Techniques used:
Lateral Movement
Select any Techniques used:
Persistence
Select any Techniques used:
Privilege Escalation
Select any Techniques used:
Topic Tags
Select the tags that apply to this CVE (Assessment added tags are disabled and cannot be removed)
What makes this of high-value to an attacker?
What makes this of low-value to an attacker?
Description
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
Data provided by the National Vulnerability Database (NVD)
Base Score:
7.5 High
Impact Score:
3.6
Exploitability Score:
3.9
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
None
Integrity (I):
None
Availability (A):
High
General Information
Offensive Application
Unknown
Utility Class
Unknown
Ports
Unknown
OS
Unknown
Vulnerable Versions
Snapdragon AR8035
Snapdragon FastConnect 7800
Snapdragon QCA6584AU
Snapdragon QCA6698AQ
Snapdragon QCA8081
Snapdragon QCA8337
Snapdragon QCC710
Snapdragon QCN6224
Snapdragon QCN6274
Snapdragon QFW7114
Snapdragon QFW7124
Snapdragon SDM429W
Snapdragon SDX80M
Snapdragon SM7675
Snapdragon SM7675P
Snapdragon SM8635
Snapdragon SM8635P
Snapdragon Snapdragon 429 Mobile Platform
Snapdragon Snapdragon 8 Gen 3 Mobile Platform
Snapdragon Snapdragon Auto 5G Modem-RF Gen 2
Snapdragon Snapdragon Wear 4100+ Platform
Snapdragon Snapdragon X72 5G Modem-RF System
Snapdragon Snapdragon X75 5G Modem-RF System
Snapdragon WCD9340
Snapdragon WCD9370
Snapdragon WCD9375
Snapdragon WCD9390
Snapdragon WCD9395
Snapdragon WCN3610
Snapdragon WCN3620
Snapdragon WCN3660B
Snapdragon WCN3680B
Snapdragon WCN3980
Snapdragon WCN6755
Snapdragon WSA8830
Snapdragon WSA8832
Snapdragon WSA8835
Snapdragon WSA8840
Snapdragon WSA8845
Snapdragon WSA8845H
Prerequisites
Unknown
Discovered By
Unknown
PoC Author
Unknown
Metasploit Module
Unknown
Reporter
Unknown
Vendors
Products
- ar8035 firmware
- fastconnect 7800 firmware
- qca6584au firmware
- qca6698aq firmware
- qca8081 firmware
- qca8337 firmware
- qcc710 firmware
- qcn6224 firmware
- qcn6274 firmware
- qfw7114 firmware
- qfw7124 firmware
- sdm429w firmware
- sdx80m firmware
- sm7675 firmware
- sm7675p firmware
- sm8635 firmware
- sm8635p firmware
- snapdragon 429 mobile firmware
- snapdragon 8 gen 3 mobile firmware
- snapdragon auto 5g modem rf gen 2 firmware
- snapdragon wear 4100+ firmware
- snapdragon x72 5g modem rf system firmware
- snapdragon x75 5g modem rf system firmware
- wcd9340 firmware
- wcd9370 firmware
- wcd9375 firmware
- wcd9390 firmware
- wcd9395 firmware
- wcn3610 firmware
- wcn3620 firmware
- wcn3660b firmware
- wcn3680b firmware
- wcn3980 firmware
- wcn6755 firmware
- wsa8830 firmware
- wsa8832 firmware
- wsa8835 firmware
- wsa8840 firmware
- wsa8845 firmware
- wsa8845h firmware
References
Additional Info
Authenticated
Unknown
Exploitable
Unknown
Reliability
Unknown
Stability
Unknown
Available Mitigations
Unknown
Shelf Life
Unknown
Userbase/Installbase
Unknown
Patch Effectiveness
Unknown
Rapid7
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: