CVE-2024-38408
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- EPSS probability
- 0.14%
- CWE
- CWE-310
- Published
- 2024-11-04
- Last modified
- 2026-03-13
Affected products
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
Weakness type
Related vulnerabilities
- CVE-2026-86280 — SourceCodester Syllabus-Aligned Learning Management & Examination System cict_portal.sql cleartext storage
- CVE-2026-82699 — sambitraj Student Management System Password aca.sql cleartext storage
- CVE-2026-82555 — TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values
- CVE-2026-81836 — RooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmission
- CVE-2026-77151 — lin-snow Ech0 crypto.go MD5Encrypt risky encryption
- CVE-2026-19896 — mangroup dtale Flask Session Cookie app.py build_secret_key random values
- CVE-2026-19891 — TRENDnet TEW-WLC100 IKE Phase 1 Aggressive Mode racoon.conf missing encryption
- CVE-2026-17616 — Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access