Information disclosure while parsing the OCI IE with invalid length.
Conclusion & alert: CVE-2024-49838 is rated Moderate Risk (46.1/100): CVSS High severity, with low exploitation likelihood (EPSS 0.17%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-17 | 0.11% | 0.17% | +0.06% |
| 2 | 2025-11-21 | 0.15% | 0.11% | -0.04% |
| 3 | 2025-11-20 | — | 0.15% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.2 | 3.1 | HIGH |
|
3.9 | 4.2 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| qualcomm | ar8035_firmware | — | cpe:2.3:o:qualcomm:ar8035_firmware:-:*:*:*:*:*:*:* |
| qualcomm | fastconnect_6200_firmware | — | cpe:2.3:o:qualcomm:fastconnect_6200_firmware:-:*:*:*:*:*:*:* |
| qualcomm | fastconnect_6700_firmware | — | cpe:2.3:o:qualcomm:fastconnect_6700_firmware:-:*:*:*:*:*:*:* |
| qualcomm | fastconnect_6800_firmware | — | cpe:2.3:o:qualcomm:fastconnect_6800_firmware:-:*:*:*:*:*:*:* |
| qualcomm | fastconnect_6900_firmware | — | cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:* |
| qualcomm | fastconnect_7800_firmware | — | cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9628_firmware | — | cpe:2.3:o:qualcomm:mdm9628_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qam8255p_firmware | — | cpe:2.3:o:qualcomm:qam8255p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qam8295p_firmware | — | cpe:2.3:o:qualcomm:qam8295p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qam8620p_firmware | — | cpe:2.3:o:qualcomm:qam8620p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qam8650p_firmware | — | cpe:2.3:o:qualcomm:qam8650p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qam8775p_firmware | — | cpe:2.3:o:qualcomm:qam8775p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qamsrv1h_firmware | — | cpe:2.3:o:qualcomm:qamsrv1h_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qamsrv1m_firmware | — | cpe:2.3:o:qualcomm:qamsrv1m_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6174a_firmware | — | cpe:2.3:o:qualcomm:qca6174a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6391_firmware | — | cpe:2.3:o:qualcomm:qca6391_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6426_firmware | — | cpe:2.3:o:qualcomm:qca6426_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6436_firmware | — | cpe:2.3:o:qualcomm:qca6436_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6554a_firmware | — | cpe:2.3:o:qualcomm:qca6554a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6564a_firmware | — | cpe:2.3:o:qualcomm:qca6564a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6564au_firmware | — | cpe:2.3:o:qualcomm:qca6564au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6574_firmware | — | cpe:2.3:o:qualcomm:qca6574_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6574a_firmware | — | cpe:2.3:o:qualcomm:qca6574a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6574au_firmware | — | cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6584au_firmware | — | cpe:2.3:o:qualcomm:qca6584au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6595_firmware | — | cpe:2.3:o:qualcomm:qca6595_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6595au_firmware | — | cpe:2.3:o:qualcomm:qca6595au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6678aq_firmware | — | cpe:2.3:o:qualcomm:qca6678aq_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6688aq_firmware | — | cpe:2.3:o:qualcomm:qca6688aq_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6696_firmware | — | cpe:2.3:o:qualcomm:qca6696_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6698aq_firmware | — | cpe:2.3:o:qualcomm:qca6698aq_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6777aq_firmware | — | cpe:2.3:o:qualcomm:qca6777aq_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6787aq_firmware | — | cpe:2.3:o:qualcomm:qca6787aq_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6797aq_firmware | — | cpe:2.3:o:qualcomm:qca6797aq_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca8081_firmware | — | cpe:2.3:o:qualcomm:qca8081_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca8337_firmware | — | cpe:2.3:o:qualcomm:qca8337_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca9367_firmware | — | cpe:2.3:o:qualcomm:qca9367_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca9377_firmware | — | cpe:2.3:o:qualcomm:qca9377_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcc2073_firmware | — | cpe:2.3:o:qualcomm:qcc2073_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcc2076_firmware | — | cpe:2.3:o:qualcomm:qcc2076_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcc710_firmware | — | cpe:2.3:o:qualcomm:qcc710_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm4325_firmware | — | cpe:2.3:o:qualcomm:qcm4325_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm4490_firmware | — | cpe:2.3:o:qualcomm:qcm4490_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm5430_firmware | — | cpe:2.3:o:qualcomm:qcm5430_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm6125_firmware | — | cpe:2.3:o:qualcomm:qcm6125_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm6490_firmware | — | cpe:2.3:o:qualcomm:qcm6490_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm8550_firmware | — | cpe:2.3:o:qualcomm:qcm8550_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcn6024_firmware | — | cpe:2.3:o:qualcomm:qcn6024_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcn6224_firmware | — | cpe:2.3:o:qualcomm:qcn6224_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcn6274_firmware | — | cpe:2.3:o:qualcomm:qcn6274_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcn9024_firmware | — | cpe:2.3:o:qualcomm:qcn9024_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcn9274_firmware | — | cpe:2.3:o:qualcomm:qcn9274_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs4490_firmware | — | cpe:2.3:o:qualcomm:qcs4490_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs5430_firmware | — | cpe:2.3:o:qualcomm:qcs5430_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs6125_firmware | — | cpe:2.3:o:qualcomm:qcs6125_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs615_firmware | — | cpe:2.3:o:qualcomm:qcs615_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs6490_firmware | — | cpe:2.3:o:qualcomm:qcs6490_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs7230_firmware | — | cpe:2.3:o:qualcomm:qcs7230_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs8250_firmware | — | cpe:2.3:o:qualcomm:qcs8250_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs8300_firmware | — | cpe:2.3:o:qualcomm:qcs8300_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs8550_firmware | — | cpe:2.3:o:qualcomm:qcs8550_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs9100_firmware | — | cpe:2.3:o:qualcomm:qcs9100_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qep8111_firmware | — | cpe:2.3:o:qualcomm:qep8111_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qfw7114_firmware | — | cpe:2.3:o:qualcomm:qfw7114_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qfw7124_firmware | — | cpe:2.3:o:qualcomm:qfw7124_firmware:-:*:*:*:*:*:*:* |
| qualcomm | video_collaboration_vc1_platform_firmware | — | cpe:2.3:o:qualcomm:video_collaboration_vc1_platform_firmware:-:*:*:*:*:*:*:* |
| qualcomm | video_collaboration_vc3_platform_firmware | — | cpe:2.3:o:qualcomm:video_collaboration_vc3_platform_firmware:-:*:*:*:*:*:*:* |
| qualcomm | video_collaboration_vc5_platform_firmware | — | cpe:2.3:o:qualcomm:video_collaboration_vc5_platform_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa6155p_firmware | — | cpe:2.3:o:qualcomm:sa6155p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa7255p_firmware | — | cpe:2.3:o:qualcomm:sa7255p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa7775p_firmware | — | cpe:2.3:o:qualcomm:sa7775p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8155p_firmware | — | cpe:2.3:o:qualcomm:sa8155p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8195p_firmware | — | cpe:2.3:o:qualcomm:sa8195p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8255p_firmware | — | cpe:2.3:o:qualcomm:sa8255p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8295p_firmware | — | cpe:2.3:o:qualcomm:sa8295p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8530p_firmware | — | cpe:2.3:o:qualcomm:sa8530p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8540p_firmware | — | cpe:2.3:o:qualcomm:sa8540p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8620p_firmware | — | cpe:2.3:o:qualcomm:sa8620p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8650p_firmware | — | cpe:2.3:o:qualcomm:sa8650p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8770p_firmware | — | cpe:2.3:o:qualcomm:sa8770p_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://docs.qualcomm.com/product/publicresources/securitybulletin/february-2025-bulletin.html | Patch Vendor Advisory |