« Volver al listado

Qualcomm

Qualcomm Qca4004 Firmware: vulnerabilidades y CVE

Qualcomm Qca4004 Firmware tiene 163 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 29 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE163
Últimos 12 meses2
Críticas29
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-27054Alta (7.8)0.09%—9 oct 2025
Memory corruption while processing a malformed license file during reboot.
CVE-2025-27053Alta (7.8)0.09%—9 oct 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-21465Media (6.5)0.09%—6 ago 2025
Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464Media (6.5)0.09%—6 ago 2025
Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2024-43046Media (5.5)0.11%—7 abr 2025
There may be information disclosure during memory re-allocation in TZ Secure OS.
CVE-2024-38426Media (5.3)0.27%—3 mar 2025
While processing the authentication message in UE, improper authentication may lead to information disclosure.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-33016Media (6.8)0.15%—2 sept 2024
memory corruption when an invalid firehose patch command is invoked.
CVE-2024-23362Alta (7.1)0.12%—2 sept 2024
Cryptographic issue while parsing RSA keys in COBR format.
CVE-2024-23359Alta (8.2)0.26%—2 sept 2024
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
CVE-2024-23353Alta (7.5)0.35%—5 ago 2024
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2024-21469Alta (7.8)0.10%—1 jul 2024
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
CVE-2024-21465Alta (7.8)0.10%—1 jul 2024
Memory corruption while processing key blob passed by the user.
CVE-2024-21462Media (5.5)0.09%—1 jul 2024
Transient DOS while loading the TA ELF file.
CVE-2024-21461Alta (7.8)0.10%—1 jul 2024
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
CVE-2023-43551Alta (7.5)0.26%—3 jun 2024
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
CVE-2023-43542Alta (7.8)0.10%—3 jun 2024
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
CVE-2023-28547Alta (7.8)0.11%—1 abr 2024
Memory corruption in SPS Application while requesting for public key in sorter TA.
CVE-2023-33066Alta (7.8)0.11%—4 mar 2024
Memory corruption in Audio while processing RT proxy port register driver.
CVE-2023-33072Alta (7.8)0.11%—6 feb 2024
Memory corruption in Core while processing control functions.
CVE-2023-33033Alta (7.8)0.12%—2 ene 2024
Memory corruption in Audio during playback with speaker protection.
CVE-2023-33032Alta (7.8)0.12%—2 ene 2024
Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.
CVE-2023-33030Alta (7.8)0.12%—2 ene 2024
Memory corruption in HLOS while running playready use-case.
CVE-2023-33018Alta (7.8)0.11%—5 dic 2023
Memory corruption while using the UIM diag command to get the operators name.
CVE-2023-33017Alta (7.8)0.16%—5 dic 2023
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
CVE-2023-28586Media (6.5)0.14%—5 dic 2023
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
CVE-2023-28585Alta (8.8)0.14%—5 dic 2023
Memory corruption while loading an ELF segment in TEE Kernel.
CVE-2023-28551Alta (7.8)0.12%—5 dic 2023
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
CVE-2023-28550Alta (7.8)0.12%—5 dic 2023
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
CVE-2023-28546Alta (7.8)0.11%—5 dic 2023
Memory Corruption in SPS Application while exporting public key in sorter TA.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation3
  2. T1059 Command and Scripting Interpreter2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm