« Volver al listado

Qualcomm

Qualcomm Qca4020 Firmware: vulnerabilidades y CVE

Qualcomm Qca4020 Firmware tiene 121 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 36 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE121
Últimos 12 meses0
Críticas36
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2020-11261Alta (7.8)1.6%⚠ Explotación activa9 jun 2021
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…
CVE-2021-1905Alta (7.8)1.5%⚠ Explotación activa7 may 2021
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33080Alta (7.5)0.34%—5 dic 2023
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
CVE-2023-33017Alta (7.8)0.16%—5 dic 2023
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
CVE-2023-33059Alta (7.8)0.11%—7 nov 2023
Memory corruption in Audio while processing the VOC packet data from ADSP.
CVE-2023-28560Alta (7.8)0.12%—5 sept 2023
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
CVE-2023-28537Alta (7.8)0.12%—8 ago 2023
Memory corruption while allocating memory in COmxApeDec module in Audio.
CVE-2023-22666Alta (7.8)0.12%—8 ago 2023
Memory Corruption in Audio while playing amrwbplus clips with modified content.
CVE-2023-21626Alta (7.1)0.11%—8 ago 2023
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
CVE-2023-21625Alta (7.5)0.35%—8 ago 2023
Information disclosure in Network Services due to buffer over-read while the device receives DNS response.
CVE-2022-40510Crítica (9.8)0.43%—8 ago 2023
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
CVE-2022-40531Alta (7.8)0.12%—10 mar 2023
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
CVE-2022-25655Alta (7.8)0.12%—10 mar 2023
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
CVE-2022-40512Alta (7.5)0.42%—12 feb 2023
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
CVE-2022-33229Alta (7.5)0.38%—12 feb 2023
Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets.
CVE-2022-25738Alta (7.5)0.38%—12 feb 2023
Information disclosure in modem due to buffer over-red while performing checksum of packet received
CVE-2022-25735Alta (7.5)0.41%—12 feb 2023
Denial of service in modem due to missing null check while processing TCP or UDP packets from server
CVE-2022-25734Alta (7.5)0.41%—12 feb 2023
Denial of service in modem due to missing null check while processing IP packets with padding
CVE-2022-25733Alta (7.5)0.41%—12 feb 2023
Denial of service in modem due to null pointer dereference while processing DNS packets
CVE-2022-25732Alta (7.5)0.38%—12 feb 2023
Information disclosure in modem due to buffer over read in dns client due to missing length check
CVE-2022-25729Crítica (9.8)0.44%—12 feb 2023
Memory corruption in modem due to improper length check while copying into memory
CVE-2022-25728Alta (7.5)0.38%—12 feb 2023
Information disclosure in modem due to buffer over-read while processing response from DNS server
CVE-2022-33286Media (6.5)0.38%—9 ene 2023
Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.
CVE-2022-33285Media (6.5)0.38%—9 ene 2023
Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.
CVE-2022-22079Media (4.6)0.17%—9 ene 2023
Denial of service while processing fastboot flash command on mmc due to buffer over read
CVE-2022-33238Alta (7.5)0.42%—13 dic 2022
Transient DOS due to loop with unreachable exit condition in WLAN while processing an incoming FTM frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,…
CVE-2022-33235Alta (7.5)0.39%—13 dic 2022
Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics…
CVE-2022-33239Alta (7.5)0.41%—15 nov 2022
Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics…
CVE-2022-25743Alta (7.8)0.15%—15 nov 2022
Memory corruption in graphics due to use-after-free while importing graphics buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…
CVE-2022-25742Alta (7.5)0.41%—15 nov 2022
Denial of service in modem due to infinite loop while parsing IGMPv2 packet from server in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music
CVE-2022-25727Crítica (9.8)0.45%—15 nov 2022
Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music
CVE-2022-25724Alta (7.8)0.12%—15 nov 2022
Memory corruption in graphics due to buffer overflow while validating the user address in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter2
  2. T1068 Exploitation for Privilege Escalation2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm