« Back to list

Qualcomm

Qualcomm Apq8053-ac Firmware: vulnerabilities and CVEs

Qualcomm Apq8053-ac Firmware has 19 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 1 are listed by CISA as actively exploited.

CVEs19
Last 12 months0
Critical1
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-33063High (7.8)0.67%⚠ Active exploitationDec 5, 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-21461High (7.8)0.10%—Jul 1, 2024
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
CVE-2023-33080High (7.5)0.34%—Dec 5, 2023
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
CVE-2023-33063High (7.8)0.67%⚠ Active exploitationDec 5, 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2023-33018High (7.8)0.11%—Dec 5, 2023
Memory corruption while using the UIM diag command to get the operators name.
CVE-2023-33059High (7.8)0.11%—Nov 7, 2023
Memory corruption in Audio while processing the VOC packet data from ADSP.
CVE-2023-24850High (7.8)0.12%—Oct 3, 2023
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
CVE-2023-24848High (7.5)0.36%—Oct 3, 2023
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
CVE-2023-22385Critical (9.8)0.42%—Oct 3, 2023
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
CVE-2023-28537High (7.8)0.12%—Aug 8, 2023
Memory corruption while allocating memory in COmxApeDec module in Audio.
CVE-2022-40521High (7.5)0.35%—Jun 6, 2023
Transient DOS due to improper authorization in Modem
CVE-2022-33264High (7.8)0.11%—Jun 6, 2023
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
CVE-2022-22076Medium (5.5)0.11%—Jun 6, 2023
information disclosure due to cryptographic issue in Core during RPMB read request.
CVE-2022-40504High (7.5)0.38%—May 2, 2023
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
CVE-2023-21666High (7.8)0.18%—May 2, 2023
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
CVE-2023-21665High (7.8)0.18%—May 2, 2023
Memory corruption in Graphics while importing a file.
CVE-2022-40532High (7.8)0.12%—Apr 13, 2023
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
CVE-2022-40503High (7.5)0.41%—Apr 13, 2023
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
CVE-2022-33302High (7.8)0.12%—Apr 13, 2023
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
CVE-2022-33289Medium (6.8)0.19%—Apr 13, 2023
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1068 Exploitation for Privilege Escalation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm