Qualcomm
Qualcomm Snapdragon X70 Modem-rf System Firmware: vulnerabilidades y CVE
Qualcomm Snapdragon X70 Modem-rf System Firmware tiene 74 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE74
Últimos 12 meses4
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-24084 | Alta (7.5) | 0.25% | — | 4 ago 2026 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. |
| CVE-2025-47392 | Alta (8.8) | 0.28% | — | 6 abr 2026 | Memory corruption when decoding corrupted satellite data files with invalid signature offsets. |
| CVE-2025-47383 | Alta (7.2) | 0.14% | — | 2 mar 2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. |
| CVE-2025-47323 | Alta (7.8) | 0.09% | — | 18 dic 2025 | Memory corruption while routing GPR packets between user and root when handling large data packet. |
| CVE-2025-27034 | Crítica (9.8) | 0.40% | — | 24 sept 2025 | Memory corruption while selecting the PLMN from SOR failed list. |
| CVE-2025-21482 | Alta (7.1) | 0.08% | — | 24 sept 2025 | Cryptographic issue while performing RSA PKCS padding decoding. |
| CVE-2025-21477 | Alta (7.5) | 0.21% | — | 6 ago 2025 | Transient DOS while processing CCCH data when NW sends data with invalid length. |
| CVE-2025-21465 | Media (6.5) | 0.09% | — | 6 ago 2025 | Information disclosure while processing the hash segment in an MBN file. |
| CVE-2025-21464 | Media (6.5) | 0.09% | — | 6 ago 2025 | Information disclosure while reading data from an image using specified offset and size parameters. |
| CVE-2024-45549 | Alta (7.7) | 0.12% | — | 7 abr 2025 | Information disclosure while creating MQ channels. |
| CVE-2024-43046 | Media (5.5) | 0.11% | — | 7 abr 2025 | There may be information disclosure during memory re-allocation in TZ Secure OS. |
| CVE-2024-33056 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
| CVE-2024-23385 | Media (6.5) | 0.25% | — | 4 nov 2024 | Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE. |
| CVE-2024-33016 | Media (6.8) | 0.15% | — | 2 sept 2024 | memory corruption when an invalid firehose patch command is invoked. |
| CVE-2024-23362 | Alta (7.1) | 0.12% | — | 2 sept 2024 | Cryptographic issue while parsing RSA keys in COBR format. |
| CVE-2024-23359 | Alta (8.2) | 0.26% | — | 2 sept 2024 | Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network. |
| CVE-2024-23353 | Alta (7.5) | 0.35% | — | 5 ago 2024 | Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. |
| CVE-2024-23352 | Alta (7.5) | 0.35% | — | 5 ago 2024 | Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA. |
| CVE-2024-21469 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption when an invoke call and a TEE call are bound for the same trusted application. |
| CVE-2024-21465 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption while processing key blob passed by the user. |
| CVE-2024-21462 | Media (5.5) | 0.09% | — | 1 jul 2024 | Transient DOS while loading the TA ELF file. |
| CVE-2023-28578 | Alta (7.8) | 0.12% | — | 4 mar 2024 | Memory corruption in Core Services while executing the command for removing a single event listener. |
| CVE-2023-33076 | Alta (7.8) | 0.11% | — | 6 feb 2024 | Memory corruption in Core when updating rollback version for TA and OTA feature is enabled. |
| CVE-2023-33072 | Alta (7.8) | 0.11% | — | 6 feb 2024 | Memory corruption in Core while processing control functions. |
| CVE-2023-33060 | Media (5.5) | 0.10% | — | 6 feb 2024 | Transient DOS in Core when DDR memory check is called while DDR is not initialized. |
| CVE-2023-33058 | Crítica (9.1) | 0.36% | — | 6 feb 2024 | Information disclosure in Modem while processing SIB5. |
| CVE-2023-33057 | Alta (7.5) | 0.32% | — | 6 feb 2024 | Transient DOS in Multi-Mode Call Processor while processing UE policy container. |
| CVE-2023-33049 | Alta (7.5) | 0.32% | — | 6 feb 2024 | Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage. |
| CVE-2023-33046 | Alta (7) | 0.08% | — | 6 feb 2024 | Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation. |
| CVE-2023-33110 | Alta (7) | 0.08% | — | 2 ene 2024 | The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.