CVE-2024-38408 is a critical cryptographic vulnerability affecting Qualcomm products, specifically when a controller receives an LMP start encryption command under unexpected conditions. With a CVSS score of 9.1, it presents a network-exploitable threat with low attack complexity, potentially leading to high confidentiality and integrity impacts without requiring user interaction. While no public exploit code or KEV listing exists, Google has reportedly fixed two Android zero-days used in targeted attacks, one of which is this vulnerability, indicating active exploitation. Community discussion and media coverage are minimal despite its critical nature.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:wsa8832_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.