Qualcomm
Qualcomm Mdm8207 Firmware: vulnerabilidades y CVE
Qualcomm Mdm8207 Firmware tiene 110 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 26 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE110
Últimos 12 meses2
Críticas26
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-47383 | Alta (7.2) | 0.14% | — | 2 mar 2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. |
| CVE-2025-27053 | Alta (7.8) | 0.09% | — | 9 oct 2025 | Memory corruption during PlayReady APP usecase while processing TA commands. |
| CVE-2025-21482 | Alta (7.1) | 0.08% | — | 24 sept 2025 | Cryptographic issue while performing RSA PKCS padding decoding. |
| CVE-2024-33056 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
| CVE-2024-23353 | Alta (7.5) | 0.35% | — | 5 ago 2024 | Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. |
| CVE-2023-43551 | Alta (7.5) | 0.26% | — | 3 jun 2024 | Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| CVE-2023-33066 | Alta (7.8) | 0.11% | — | 4 mar 2024 | Memory corruption in Audio while processing RT proxy port register driver. |
| CVE-2023-33033 | Alta (7.8) | 0.12% | — | 2 ene 2024 | Memory corruption in Audio during playback with speaker protection. |
| CVE-2023-33030 | Alta (7.8) | 0.12% | — | 2 ene 2024 | Memory corruption in HLOS while running playready use-case. |
| CVE-2023-33018 | Alta (7.8) | 0.11% | — | 5 dic 2023 | Memory corruption while using the UIM diag command to get the operators name. |
| CVE-2023-33017 | Alta (7.8) | 0.16% | — | 5 dic 2023 | Memory corruption in Boot while running a ListVars test in UEFI Menu during boot. |
| CVE-2023-28551 | Alta (7.8) | 0.12% | — | 5 dic 2023 | Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. |
| CVE-2023-28550 | Alta (7.8) | 0.12% | — | 5 dic 2023 | Memory corruption in MPP performance while accessing DSM watermark using external memory address. |
| CVE-2023-22388 | Crítica (9.8) | 0.35% | — | 7 nov 2023 | Memory Corruption in Multi-mode Call Processor while processing bit mask API. |
| CVE-2023-24849 | Alta (7.5) | 0.30% | — | 3 oct 2023 | Information Disclosure in data Modem while parsing an FMTP line in an SDP message. |
| CVE-2023-24848 | Alta (7.5) | 0.30% | — | 3 oct 2023 | Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. |
| CVE-2023-22385 | Crítica (9.8) | 0.35% | — | 3 oct 2023 | Memory Corruption in Data Modem while making a MO call or MT VOLTE call. |
| CVE-2023-21626 | Alta (7.1) | 0.11% | — | 8 ago 2023 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. |
| CVE-2022-40510 | Crítica (9.8) | 0.43% | — | 8 ago 2023 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. |
| CVE-2022-40521 | Alta (7.5) | 0.35% | — | 6 jun 2023 | Transient DOS due to improper authorization in Modem |
| CVE-2022-40507 | Alta (7.8) | 1.3% | — | 6 jun 2023 | Memory corruption due to double free in Core while mapping HLOS address to the list. |
| CVE-2022-33264 | Alta (7.8) | 0.11% | — | 6 jun 2023 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. |
| CVE-2022-22076 | Media (5.5) | 0.11% | — | 6 jun 2023 | information disclosure due to cryptographic issue in Core during RPMB read request. |
| CVE-2022-40505 | Alta (7.5) | 0.35% | — | 2 may 2023 | Information disclosure due to buffer over-read in Modem while parsing DNS hostname. |
| CVE-2022-33304 | Alta (7.5) | 0.38% | — | 2 may 2023 | Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet. |
| CVE-2022-33302 | Alta (7.8) | 0.12% | — | 13 abr 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. |
| CVE-2022-33295 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure in Modem due to buffer over-read while parsing the wms message received given the buffer and its length. |
| CVE-2022-33294 | Alta (7.5) | 0.38% | — | 13 abr 2023 | Transient DOS in Modem due to NULL pointer dereference while receiving response of lwm2m registration/update/bootstrap request message. |
| CVE-2022-33291 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length. |
| CVE-2022-33289 | Media (6.8) | 0.19% | — | 13 abr 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.