Qualcomm
Qualcomm Qca4010 Firmware: vulnerabilidades y CVE
Qualcomm Qca4010 Firmware tiene 25 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-28563 | Media (5.5) | 0.14% | — | 7 nov 2023 | Information disclosure in IOE Firmware while handling WMI command. |
| CVE-2023-28565 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while handling command streams through WMI interfaces. |
| CVE-2023-28560 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. |
| CVE-2023-28559 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload. |
| CVE-2023-21625 | Alta (7.5) | 0.35% | — | 8 ago 2023 | Information disclosure in Network Services due to buffer over-read while the device receives DNS response. |
| CVE-2023-21628 | Alta (7.8) | 0.12% | — | 6 jun 2023 | Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. |
| CVE-2022-40505 | Alta (7.5) | 0.35% | — | 2 may 2023 | Information disclosure due to buffer over-read in Modem while parsing DNS hostname. |
| CVE-2022-33291 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length. |
| CVE-2022-33287 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet. |
| CVE-2022-33222 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure due to buffer over-read while parsing DNS response packets in Modem. |
| CVE-2022-25731 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure in modem due to buffer over-read while processing packets from DNS server |
| CVE-2022-25730 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure in modem due to improper check of IP type while processing DNS server query |
| CVE-2022-25655 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload. |
| CVE-2022-33229 | Alta (7.5) | 0.38% | — | 12 feb 2023 | Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets. |
| CVE-2022-25738 | Alta (7.5) | 0.38% | — | 12 feb 2023 | Information disclosure in modem due to buffer over-red while performing checksum of packet received |
| CVE-2022-25734 | Alta (7.5) | 0.41% | — | 12 feb 2023 | Denial of service in modem due to missing null check while processing IP packets with padding |
| CVE-2022-25733 | Alta (7.5) | 0.41% | — | 12 feb 2023 | Denial of service in modem due to null pointer dereference while processing DNS packets |
| CVE-2022-25742 | Alta (7.5) | 0.41% | — | 15 nov 2022 | Denial of service in modem due to infinite loop while parsing IGMPv2 packet from server in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music |
| CVE-2022-25727 | Crítica (9.8) | 0.45% | — | 15 nov 2022 | Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music |
| CVE-2022-25674 | Crítica (9.8) | 0.30% | — | 15 nov 2022 | Cryptographic issues in WLAN during the group key handshake of the WPA/WPA2 protocol in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music |
| CVE-2022-25719 | Crítica (9.1) | 0.50% | — | 19 oct 2022 | Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,… |
| CVE-2022-25718 | Crítica (9.8) | 0.45% | — | 19 oct 2022 | Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,… |
| CVE-2021-30288 | Alta (7.8) | 0.16% | — | 20 oct 2021 | Possible stack overflow due to improper length check of TLV while copying the TLV to a local stack variable in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,… |
| CVE-2020-11269 | Alta (8.8) | 0.29% | — | 22 feb 2021 | Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics… |
| CVE-2019-14135 | Alta (7.8) | 0.20% | — | 16 abr 2020 | Possible integer overflow to buffer overflow in WLAN while parsing nonstandard NAN IE messages. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon… |