« Volver al listado

Qualcomm

Qualcomm Immersive Home 318 Platform Firmware: vulnerabilidades y CVE

Qualcomm Immersive Home 318 Platform Firmware tiene 89 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 6 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE89
Últimos 12 meses11
Críticas6
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33063Alta (7.8)0.67%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-25275Alta (7.5)0.19%—17 sept 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-25268Alta (8.8)0.11%—6 jul 2026
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
CVE-2026-24088Alta (8.2)0.07%—1 jun 2026
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
CVE-2025-59609Media (5.5)0.09%—1 jun 2026
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
CVE-2026-21367Alta (7.5)0.20%—6 abr 2026
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
CVE-2025-47339Alta (7.8)0.08%—7 ene 2026
Memory corruption while deinitializing a HDCP session.
CVE-2025-47331Media (6.1)0.08%—7 ene 2026
Information disclosure while processing a firmware event.
CVE-2025-27074Alta (7.8)0.09%—4 nov 2025
Memory corruption while processing a GP command response.
CVE-2025-27060Alta (8.8)0.09%—9 oct 2025
Memory corruption while performing SCM call with malformed inputs.
CVE-2025-27040Media (6.5)0.08%—9 oct 2025
Information disclosure may occur while processing the hypervisor log.
CVE-2025-27059Alta (8.8)0.09%—9 oct 2025
Memory corruption while performing SCM call.
CVE-2025-47326Alta (7.5)0.24%—24 sept 2025
Transient DOS while handling command data during power control processing.
CVE-2025-47318Alta (7.5)0.21%—24 sept 2025
Transient DOS while parsing the EPTM test control message to get the test pattern.
CVE-2025-21482Alta (7.1)0.08%—24 sept 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-27073Alta (7.5)0.21%—6 ago 2025
Transient DOS while creating NDP instance.
CVE-2025-27066Alta (7.5)0.28%—6 ago 2025
Transient DOS while processing an ANQP message.
CVE-2025-21463Alta (7.5)0.23%—3 jun 2025
Transient DOS while processing the EHT operation IE in the received beacon frame.
CVE-2025-21448Alta (7.5)0.26%—7 abr 2025
Transient DOS may occur while parsing SSID in action frames.
CVE-2025-21435Alta (7.5)0.26%—7 abr 2025
Transient DOS may occur while parsing extended IE in beacon.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-38408Crítica (9.1)0.14%—4 nov 2024
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
CVE-2024-33073Alta (8.2)0.35%—7 oct 2024
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
CVE-2024-33066Crítica (9.8)0.60%—7 oct 2024
Memory corruption while redirecting log file to any file location with any file name.
CVE-2024-33049Alta (7.5)0.32%—7 oct 2024
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
CVE-2024-33026Alta (7.5)0.28%—5 ago 2024
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.
CVE-2024-33025Alta (7.5)0.28%—5 ago 2024
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
CVE-2024-33024Alta (7.5)0.28%—5 ago 2024
Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.
CVE-2024-33019Alta (7.5)0.28%—5 ago 2024
Transient DOS while parsing the received TID-to-link mapping action frame.
CVE-2024-33018Alta (7.5)0.33%—5 ago 2024
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.
CVE-2024-33015Alta (7.5)0.28%—5 ago 2024
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application13
  2. T1068 Exploitation for Privilege Escalation10
  3. T1499.004 Application or System Exploitation8
  4. T1059 Command and Scripting Interpreter6
  5. T1499 Endpoint Denial of Service2
  6. T1005 Data from Local System1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm