Qualcomm
Qualcomm Qca4020 Firmware: vulnerabilidades y CVE
Qualcomm Qca4020 Firmware tiene 121 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 36 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE121
Últimos 12 meses0
Críticas36
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-11261 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 9 jun 2021 | Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2021-1905 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 7 may 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-33080 | Alta (7.5) | 0.34% | — | 5 dic 2023 | Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. |
| CVE-2023-33017 | Alta (7.8) | 0.16% | — | 5 dic 2023 | Memory corruption in Boot while running a ListVars test in UEFI Menu during boot. |
| CVE-2023-33059 | Alta (7.8) | 0.11% | — | 7 nov 2023 | Memory corruption in Audio while processing the VOC packet data from ADSP. |
| CVE-2023-28560 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. |
| CVE-2023-28537 | Alta (7.8) | 0.12% | — | 8 ago 2023 | Memory corruption while allocating memory in COmxApeDec module in Audio. |
| CVE-2023-22666 | Alta (7.8) | 0.12% | — | 8 ago 2023 | Memory Corruption in Audio while playing amrwbplus clips with modified content. |
| CVE-2023-21626 | Alta (7.1) | 0.11% | — | 8 ago 2023 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. |
| CVE-2023-21625 | Alta (7.5) | 0.35% | — | 8 ago 2023 | Information disclosure in Network Services due to buffer over-read while the device receives DNS response. |
| CVE-2022-40510 | Crítica (9.8) | 0.43% | — | 8 ago 2023 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. |
| CVE-2022-40531 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message. |
| CVE-2022-25655 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload. |
| CVE-2022-40512 | Alta (7.5) | 0.42% | — | 12 feb 2023 | Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon. |
| CVE-2022-33229 | Alta (7.5) | 0.38% | — | 12 feb 2023 | Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets. |
| CVE-2022-25738 | Alta (7.5) | 0.38% | — | 12 feb 2023 | Information disclosure in modem due to buffer over-red while performing checksum of packet received |
| CVE-2022-25735 | Alta (7.5) | 0.41% | — | 12 feb 2023 | Denial of service in modem due to missing null check while processing TCP or UDP packets from server |
| CVE-2022-25734 | Alta (7.5) | 0.41% | — | 12 feb 2023 | Denial of service in modem due to missing null check while processing IP packets with padding |
| CVE-2022-25733 | Alta (7.5) | 0.41% | — | 12 feb 2023 | Denial of service in modem due to null pointer dereference while processing DNS packets |
| CVE-2022-25732 | Alta (7.5) | 0.38% | — | 12 feb 2023 | Information disclosure in modem due to buffer over read in dns client due to missing length check |
| CVE-2022-25729 | Crítica (9.8) | 0.44% | — | 12 feb 2023 | Memory corruption in modem due to improper length check while copying into memory |
| CVE-2022-25728 | Alta (7.5) | 0.38% | — | 12 feb 2023 | Information disclosure in modem due to buffer over-read while processing response from DNS server |
| CVE-2022-33286 | Media (6.5) | 0.38% | — | 9 ene 2023 | Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames. |
| CVE-2022-33285 | Media (6.5) | 0.38% | — | 9 ene 2023 | Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames. |
| CVE-2022-22079 | Media (4.6) | 0.17% | — | 9 ene 2023 | Denial of service while processing fastboot flash command on mmc due to buffer over read |
| CVE-2022-33238 | Alta (7.5) | 0.42% | — | 13 dic 2022 | Transient DOS due to loop with unreachable exit condition in WLAN while processing an incoming FTM frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,… |
| CVE-2022-33235 | Alta (7.5) | 0.39% | — | 13 dic 2022 | Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics… |
| CVE-2022-33239 | Alta (7.5) | 0.41% | — | 15 nov 2022 | Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics… |
| CVE-2022-25743 | Alta (7.8) | 0.15% | — | 15 nov 2022 | Memory corruption in graphics due to use-after-free while importing graphics buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… |
| CVE-2022-25742 | Alta (7.5) | 0.41% | — | 15 nov 2022 | Denial of service in modem due to infinite loop while parsing IGMPv2 packet from server in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music |
| CVE-2022-25727 | Crítica (9.8) | 0.45% | — | 15 nov 2022 | Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music |
| CVE-2022-25724 | Alta (7.8) | 0.12% | — | 15 nov 2022 | Memory corruption in graphics due to buffer overflow while validating the user address in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.