Qualcomm
Qualcomm Mdm9630 Firmware: vulnerabilities and CVEs
Qualcomm Mdm9630 Firmware has 54 published vulnerabilities, 0 of them in the last 12 months. 18 are rated critical and 0 are listed by CISA as actively exploited.
CVEs54
Last 12 months0
Critical18
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23353 | High (7.5) | 0.35% | — | Aug 5, 2024 | Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. |
| CVE-2023-43551 | High (7.5) | 0.26% | — | Jun 3, 2024 | Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| CVE-2023-33066 | High (7.8) | 0.11% | — | Mar 4, 2024 | Memory corruption in Audio while processing RT proxy port register driver. |
| CVE-2023-33120 | High (7.8) | 0.11% | — | Jan 2, 2024 | Memory corruption in Audio when memory map command is executed consecutively in ADSP. |
| CVE-2023-33033 | High (7.8) | 0.12% | — | Jan 2, 2024 | Memory corruption in Audio during playback with speaker protection. |
| CVE-2023-28550 | High (7.8) | 0.12% | — | Dec 5, 2023 | Memory corruption in MPP performance while accessing DSM watermark using external memory address. |
| CVE-2023-33059 | High (7.8) | 0.11% | — | Nov 7, 2023 | Memory corruption in Audio while processing the VOC packet data from ADSP. |
| CVE-2023-24848 | High (7.5) | 0.36% | — | Oct 3, 2023 | Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. |
| CVE-2023-22385 | Critical (9.8) | 0.42% | — | Oct 3, 2023 | Memory Corruption in Data Modem while making a MO call or MT VOLTE call. |
| CVE-2022-40521 | High (7.5) | 0.35% | — | Jun 6, 2023 | Transient DOS due to improper authorization in Modem |
| CVE-2022-33264 | High (7.8) | 0.11% | — | Jun 6, 2023 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. |
| CVE-2022-33302 | High (7.8) | 0.12% | — | Apr 13, 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. |
| CVE-2022-33289 | Medium (6.8) | 0.19% | — | Apr 13, 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. |
| CVE-2022-33213 | High (8.8) | 0.41% | — | Mar 10, 2023 | Memory corruption in modem due to buffer overflow while processing a PPP packet |
| CVE-2022-25705 | High (7.8) | 0.13% | — | Mar 10, 2023 | Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response |
| CVE-2022-25694 | High (7.8) | 0.12% | — | Mar 10, 2023 | Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM |
| CVE-2022-33233 | High (7.8) | 0.12% | — | Feb 12, 2023 | Memory corruption due to configuration weakness in modem wile sending command to write protected files. |
| CVE-2022-25695 | High (7.8) | 0.13% | — | Dec 13, 2022 | Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2022-25682 | High (7.8) | 0.13% | — | Dec 13, 2022 | Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
| CVE-2022-25720 | Critical (9.8) | 0.45% | — | Oct 19, 2022 | Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,… |
| CVE-2022-25719 | Critical (9.1) | 0.50% | — | Oct 19, 2022 | Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,… |
| CVE-2021-30284 | Critical (9.1) | 0.61% | — | Nov 12, 2021 | Possible information exposure and denial of service due to NAS not dropping messages when integrity check fails in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2021-30255 | High (7.8) | 0.16% | — | Nov 12, 2021 | Possible buffer overflow due to improper input validation in PDM DIAG command in FTM in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,… |
| CVE-2021-30254 | High (7.8) | 0.16% | — | Nov 12, 2021 | Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-1975 | Critical (9.8) | 0.87% | — | Nov 12, 2021 | Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-1973 | High (7.8) | 0.15% | — | Nov 12, 2021 | A FTM Diag command can allow an arbitrary write into modem OS space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… |
| CVE-2021-1924 | Medium (5.5) | 0.17% | — | Nov 12, 2021 | Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,… |
| CVE-2021-1959 | High (7.8) | 0.17% | — | Oct 20, 2021 | Possible memory corruption due to lack of bound check of input index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… |
| CVE-2021-30261 | High (7.8) | 0.16% | — | Sep 17, 2021 | Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2021-1909 | High (7.8) | 0.16% | — | Sep 9, 2021 | Buffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer… |