« Back to list

Qualcomm

Qualcomm Msm8920 Firmware: vulnerabilities and CVEs

Qualcomm Msm8920 Firmware has 207 published vulnerabilities, 0 of them in the last 12 months. 90 are rated critical and 1 are listed by CISA as actively exploited.

CVEs207
Last 12 months0
Critical90
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2020-11261High (7.8)1.6%⚠ Active exploitationJun 9, 2021
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-21626High (7.1)0.11%—Aug 8, 2023
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
CVE-2022-40510Critical (9.8)0.43%—Aug 8, 2023
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
CVE-2022-33213High (8.8)0.41%—Mar 10, 2023
Memory corruption in modem due to buffer overflow while processing a PPP packet
CVE-2022-25705High (7.8)0.13%—Mar 10, 2023
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
CVE-2022-25694High (7.8)0.12%—Mar 10, 2023
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
CVE-2022-33233High (7.8)0.12%—Feb 12, 2023
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
CVE-2022-25695High (7.8)0.13%—Dec 13, 2022
Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
CVE-2022-25682High (7.8)0.13%—Dec 13, 2022
Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…
CVE-2022-25719Critical (9.1)0.50%—Oct 19, 2022
Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,…
CVE-2022-25718Critical (9.8)0.45%—Oct 19, 2022
Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,…
CVE-2022-22091High (7.5)0.45%—Sep 16, 2022
Improper authorization of a replayed LTE security mode command can lead to a denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2022-22062Critical (9.1)0.34%—Sep 2, 2022
An out-of-bounds read can occur while parsing a server certificate due to improper length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon…
CVE-2021-35135Medium (5.5)0.11%—Sep 2, 2022
A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…
CVE-2021-35083Critical (9.1)0.52%—Jun 14, 2022
Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,…
CVE-2021-35072High (7.8)0.16%—Jun 14, 2022
Possible buffer overflow due to improper validation of array index while processing external DIAG command in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…
CVE-2021-30284Critical (9.1)0.61%—Nov 12, 2021
Possible information exposure and denial of service due to NAS not dropping messages when integrity check fails in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
CVE-2021-30255High (7.8)0.16%—Nov 12, 2021
Possible buffer overflow due to improper input validation in PDM DIAG command in FTM in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,…
CVE-2021-30254High (7.8)0.16%—Nov 12, 2021
Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-1975Critical (9.8)0.87%—Nov 12, 2021
Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-1973High (7.8)0.15%—Nov 12, 2021
A FTM Diag command can allow an arbitrary write into modem OS space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…
CVE-2021-1924Medium (5.5)0.17%—Nov 12, 2021
Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,…
CVE-2021-1959High (7.8)0.17%—Oct 20, 2021
Possible memory corruption due to lack of bound check of input index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…
CVE-2021-30261High (7.8)0.16%—Sep 17, 2021
Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
CVE-2021-1946Critical (9.8)0.80%—Sep 9, 2021
Null Pointer Dereference may occur due to improper validation while processing crafted SDP body in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-1935Medium (5.5)0.13%—Sep 9, 2021
Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-1933Critical (9.8)0.80%—Sep 9, 2021
UE assertion is possible due to improper validation of invite message with SDP body in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
CVE-2021-1909High (7.8)0.16%—Sep 9, 2021
Buffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer…
CVE-2021-1920Critical (9.8)0.80%—Sep 8, 2021
Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,…
CVE-2021-1919Critical (9.8)0.80%—Sep 8, 2021
Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-1916Critical (9.8)0.80%—Sep 8, 2021
Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1068 Exploitation for Privilege Escalation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm