« Back to list

Qualcomm

Qualcomm Mdm8215m Firmware: vulnerabilities and CVEs

Qualcomm Mdm8215m Firmware has 30 published vulnerabilities, 0 of them in the last 12 months. 11 are rated critical and 0 are listed by CISA as actively exploited.

CVEs30
Last 12 months0
Critical11
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-33066High (7.8)0.11%—Mar 4, 2024
Memory corruption in Audio while processing RT proxy port register driver.
CVE-2023-33018High (7.8)0.11%—Dec 5, 2023
Memory corruption while using the UIM diag command to get the operators name.
CVE-2023-24849High (7.5)0.36%—Oct 3, 2023
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
CVE-2023-24848High (7.5)0.36%—Oct 3, 2023
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
CVE-2022-40521High (7.5)0.35%—Jun 6, 2023
Transient DOS due to improper authorization in Modem
CVE-2022-33264High (7.8)0.11%—Jun 6, 2023
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
CVE-2022-33302High (7.8)0.12%—Apr 13, 2023
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
CVE-2022-33289Medium (6.8)0.19%—Apr 13, 2023
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
CVE-2022-33213High (8.8)0.41%—Mar 10, 2023
Memory corruption in modem due to buffer overflow while processing a PPP packet
CVE-2022-25694High (7.8)0.12%—Mar 10, 2023
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
CVE-2022-25682High (7.8)0.13%—Dec 13, 2022
Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…
CVE-2022-25720Critical (9.8)0.45%—Oct 19, 2022
Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,…
CVE-2021-35115High (7.8)0.18%—Apr 1, 2022
Improper handling of multiple session supported by PVM backend can lead to use after free in Snapdragon Auto, Snapdragon Mobile
CVE-2021-30270High (7.8)0.15%—Jan 3, 2022
Possible null pointer dereference in thread profile trap handler due to lack of thread ID validation before dereferencing it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…
CVE-2021-30268High (7.8)0.15%—Jan 3, 2022
Possible heap Memory Corruption Issue due to lack of input validation when sending HWTC IQ Capture command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…
CVE-2021-30284Critical (9.1)0.61%—Nov 12, 2021
Possible information exposure and denial of service due to NAS not dropping messages when integrity check fails in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
CVE-2021-1975Critical (9.8)0.87%—Nov 12, 2021
Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-1973High (7.8)0.15%—Nov 12, 2021
A FTM Diag command can allow an arbitrary write into modem OS space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…
CVE-2021-30261High (7.8)0.16%—Sep 17, 2021
Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
CVE-2021-1972Critical (9.8)0.81%—Sep 8, 2021
Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
CVE-2021-1920Critical (9.8)0.80%—Sep 8, 2021
Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,…
CVE-2021-1916Critical (9.8)0.80%—Sep 8, 2021
Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
CVE-2021-1955High (7.5)0.59%—Jul 13, 2021
Denial of service in SAP case due to improper handling of connections when association is rejected in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,…
CVE-2020-11292High (7.8)0.81%—Jun 9, 2021
Possible buffer overflow in voice service due to lack of input validation of parameters in QMI Voice API in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…
CVE-2020-11279Critical (9.8)0.82%—May 7, 2021
Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
CVE-2020-11251Critical (9.1)0.94%—Apr 7, 2021
Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
CVE-2020-11191Critical (9.1)0.94%—Apr 7, 2021
Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon…
CVE-2020-11166Critical (9.1)0.92%—Mar 17, 2021
Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC header in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…
CVE-2020-11177High (8.8)0.17%—Feb 22, 2021
User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and device lock in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer…
CVE-2020-11170Critical (9.8)0.83%—Feb 22, 2021
Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…

Other products by Qualcomm