« Volver al listado

Qualcomm

Qualcomm Mdm8207 Firmware: vulnerabilidades y CVE

Qualcomm Mdm8207 Firmware tiene 110 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 26 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE110
Últimos 12 meses2
Críticas26
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-47383Alta (7.2)0.14%—2 mar 2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
CVE-2025-27053Alta (7.8)0.09%—9 oct 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-21482Alta (7.1)0.08%—24 sept 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-23353Alta (7.5)0.35%—5 ago 2024
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2023-43551Alta (7.5)0.26%—3 jun 2024
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
CVE-2023-33066Alta (7.8)0.11%—4 mar 2024
Memory corruption in Audio while processing RT proxy port register driver.
CVE-2023-33033Alta (7.8)0.12%—2 ene 2024
Memory corruption in Audio during playback with speaker protection.
CVE-2023-33030Alta (7.8)0.12%—2 ene 2024
Memory corruption in HLOS while running playready use-case.
CVE-2023-33018Alta (7.8)0.11%—5 dic 2023
Memory corruption while using the UIM diag command to get the operators name.
CVE-2023-33017Alta (7.8)0.16%—5 dic 2023
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
CVE-2023-28551Alta (7.8)0.12%—5 dic 2023
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
CVE-2023-28550Alta (7.8)0.12%—5 dic 2023
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
CVE-2023-22388Crítica (9.8)0.35%—7 nov 2023
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
CVE-2023-24849Alta (7.5)0.30%—3 oct 2023
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
CVE-2023-24848Alta (7.5)0.30%—3 oct 2023
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
CVE-2023-22385Crítica (9.8)0.35%—3 oct 2023
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
CVE-2023-21626Alta (7.1)0.11%—8 ago 2023
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
CVE-2022-40510Crítica (9.8)0.43%—8 ago 2023
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
CVE-2022-40521Alta (7.5)0.35%—6 jun 2023
Transient DOS due to improper authorization in Modem
CVE-2022-40507Alta (7.8)1.3%—6 jun 2023
Memory corruption due to double free in Core while mapping HLOS address to the list.
CVE-2022-33264Alta (7.8)0.11%—6 jun 2023
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
CVE-2022-22076Media (5.5)0.11%—6 jun 2023
information disclosure due to cryptographic issue in Core during RPMB read request.
CVE-2022-40505Alta (7.5)0.35%—2 may 2023
Information disclosure due to buffer over-read in Modem while parsing DNS hostname.
CVE-2022-33304Alta (7.5)0.38%—2 may 2023
Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet.
CVE-2022-33302Alta (7.8)0.12%—13 abr 2023
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
CVE-2022-33295Alta (7.5)0.35%—13 abr 2023
Information disclosure in Modem due to buffer over-read while parsing the wms message received given the buffer and its length.
CVE-2022-33294Alta (7.5)0.38%—13 abr 2023
Transient DOS in Modem due to NULL pointer dereference while receiving response of lwm2m registration/update/bootstrap request message.
CVE-2022-33291Alta (7.5)0.35%—13 abr 2023
Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length.
CVE-2022-33289Media (6.8)0.19%—13 abr 2023
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation3
  2. T1041 Exfiltration Over C2 Channel1
  3. T1059 Command and Scripting Interpreter1
  4. T1210 Exploitation of Remote Services1
  5. T1552.001 Credentials In Files1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm